Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.57% | — | Code-projects Online JOB Portal | 7/3/2024 | 17/6/2026 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer." | |
| Analizada | Media (5.4) | 0.48% | — | Oretnom23 Online JOB Portal | 28/2/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Employer/EditProfile.php. The manipulation of the argument Address leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.4) | 0.52% | — | Janobe Online JOB Portal | 27/2/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Employer/ManageJob.php of the component Manage Job Page. The manipulation of the argument Qualification/Description leads to cross site… | |
| Analizada | Media (5.4) | 0.55% | — | Janobe Online JOB Portal | 27/2/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects unknown code of the file /Employer/ManageWalkin.php of the component Manage Walkin Page. The manipulation of the argument Job Title leads to cross site scripting. The attack can be initiated… | |
| Modificada | Crítica (9.8) | 0.48% | — | Wpjobportal WP JOB Portal | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.1. | |
| Modificada | Media (4.8) | 0.50% | — | Projectworlds Online JOB Portal | 7/1/2024 | 17/6/2026 | A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Admin/News.php of the component Create News Page. The manipulation of the argument News with the input </title><scRipt>alert(0x00C57D)</scRipt> leads to cross site… | |
| Modificada | Alta (8.8) | 0.22% | — | Wpjobportal WP JOB Portal | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara JOB Portal | 22/12/2023 | 17/6/2026 | Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara JOB Portal | 22/12/2023 | 17/6/2026 | Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtUser' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara JOB Portal | 21/12/2023 | 17/6/2026 | Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara JOB Portal | 21/12/2023 | 17/6/2026 | Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.83% | — | Projectworlds Online JOB Portal | 7/11/2023 | 17/6/2026 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.83% | — | Projectworlds Online JOB Portal | 7/11/2023 | 17/6/2026 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Wpjobportal WP JOB Portal | 25/9/2023 | 17/6/2026 | The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | |
| Modificada | Crítica (9.8) | 1.1% | — | Online JOB Portal Project Online JOB Portal | 23/9/2023 | 17/6/2026 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component. | |
| Modificada | Crítica (9.8) | 1.5% | — | Online JOB Portal Project Online JOB Portal | 23/9/2023 | 17/6/2026 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component. | |
| Modificada | Media (5.4) | 0.36% | — | Wpjobportal WP JOB Portal | 22/6/2023 | 17/6/2026 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | Itechscripts JOB Portal Script | 16/7/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. | |
| Modificada | Media (4.8) | 0.91% | — | Job-portal Project Job-portal | 15/10/2021 | 17/6/2026 | The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including… | |
| Modificada | Crítica (9.8) | 4.3% | — | Phpgurukul JOB Portal | 8/3/2020 | 17/6/2026 | An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution. | |
| Modificada | Media (6.5) | 1.6% | — | Entrepreneur JOB Portal Script Project Entrepreneur JOB Portal Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | |
| Modificada | Media (6.5) | 1.6% | — | Entrepreneur JOB Portal Script Project Entrepreneur JOB Portal Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of profile editing) via crafted JavaScript code in the KeySkills field. | |
| Modificada | Alta (8.8) | 0.64% | — | Entrepreneur JOB Portal Script Project Entrepreneur JOB Portal Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. | |
| Modificada | Media (5.4) | 0.65% | — | Entrepreneur JOB Portal Script Project Entrepreneur JOB Portal Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field. | |
| Modificada | Media (6.1) | 0.85% | — | Entrepreneur JOB Portal Script Project Entrepreneur JOB Portal Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar. |