Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2771▲ 6 respecto a la semana anterior
Críticas / altas1285▼ 246 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.38%—Oracle Complex Maintenance Repair AND Overhaul16/4/202417/6/2026
Vulnerabilidad en el producto Oracle Complex Maintenance, Repair and Overhaul de Oracle E-Business Suite (componente: LOV). Las versiones compatibles que se ven afectadas son 12.2.3-12.2.13. Una vulnerabilidad fácilmente explotable permite que un atacante no autenticado con acceso a la red a través de HTTP comprometa…
ModificadaAlta (7.1)0.16%—Dell Pair24/1/202417/6/2026
La versión de Dell Pair Installer anterior a la 1.2.1 contiene una vulnerabilidad de elevación de privilegios. Un usuario con privilegios bajos y acceso local al sistema podría explotar esta vulnerabilidad para eliminar archivos arbitrarios y provocar una denegación de servicio.
ModificadaMedia (6.1)0.17%—Oracle Complex Maintenance, Repair, AND Overhaul16/1/202417/6/2026
Vulnerabilidad en el producto Oracle Complex Maintenance, Repair and Overhaul de Oracle Supply Chain (componente: LOV). Las versiones compatibles que se ven afectadas son 11.5, 12.1 y 12.2. Una vulnerabilidad fácilmente explotable permite que un atacante no autenticado con acceso a la red a través de HTTP comprometa…
ModificadaAlta (8.8)0.26%—Whereyoursolutionis FIX MY Feed RSS Repair17/12/202317/6/2026
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Innovative Solutions Fix My Feed RSS Repair. Este problema afecta a Fix My Feed RSS Repair: desde n/a hasta 1.4.
ModificadaMedia (6.1)0.36%—Oretnom23 AC Repair AND Services System17/9/202317/6/2026
Una vulnerabilidad fue encontrada en SourceCodester AC Repair and Services System 1.0 y clasificada como problemática. Una función desconocida del archivo admin/?page=system_info/contact_information es afectada por esta vulnerabilidad. La manipulación del argumento telephone/mobile/address conduce a un Cross-Site…
ModificadaCrítica (9.8)0.50%—Oretnom23 AC Repair AND Services System15/7/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_inquiry of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql…
ModificadaCrítica (9.8)0.54%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated…
ModificadaMedia (6.1)0.39%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be…
ModificadaCrítica (9.8)0.54%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the…
ModificadaCrítica (9.8)0.54%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be…
ModificadaCrítica (9.8)0.49%—Oretnom23 AC Repair AND Services System11/7/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue affects some unknown processing of the file Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated…
ModificadaAlta (8.8)0.26%—984.ru FOR THE Visually Impaired26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in 984.Ru For the visually impaired plugin <= 0.58 versions.
ModificadaCrítica (9.8)0.94%—Oretnom23 AC Repair AND Services System11/5/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file /classes/Master.php?f=delete_service. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
ModificadaMedia (6.5)0.63%—Oretnom23 AC Repair AND Services System29/4/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bookings/manage_booking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.…
ModificadaMedia (6.5)0.53%—Oretnom23 AC Repair AND Services System29/4/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
ModificadaMedia (6.5)0.63%—Oretnom23 AC Repair AND Services System28/4/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_inquiry.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (6.5)0.63%—Oretnom23 AC Repair AND Services System28/4/202317/6/2026
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/bookings/view_booking.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaMedia (6.5)0.63%—Oretnom23 AC Repair AND Services System28/4/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. This affects an unknown part of the file /admin/services/view_service.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (6.5)0.63%—Oretnom23 AC Repair AND Services System28/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. Affected by this issue is some unknown functionality of the file services/view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has…
ModificadaAlta (7.8)0.43%—Wondershare Repairit4/4/202317/6/2026
An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file.
ModificadaAlta (7.8)0.51%💥 PoCOutbyte PC Repair7/9/202229/7/2026
El archivo de Instalación de Outbyte PC Repair versión 1.7.112.7856, es vulnerable a un secuestro de Dll. El archivo iertutil.dll falta, por lo que un atacante puede usar una dll maliciosa con el mismo nombre y puede conseguir privilegios de administrador
ModificadaCrítica (9.8)1.6%—Computer AND Mobile Repair Shop Management System Project Computer AND Mobile Repair Shop Management System20/1/202217/6/2026
Se presenta una vulnerabilidad de inyección SQL en Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) versión 1.0, por medio del parámetro code en la aplicación del nodo /rsms/
ModificadaCrítica (9.1)3.1%💥 PoCKeypair Project Keypair11/10/202117/6/2026
keypair es un generador de claves RSA PEM escrito en javascript. keypair implementa un montón de primitivas criptográficas por sí mismo o tomando prestado de otras bibliotecas cuando es posible, incluyendo node-forge. Se detectó un problema en el que esta biblioteca genera claves RSA idénticas a las usadas en SSH.…
ModificadaMedia (6.1)3.9%💥 ExploitSmartdatasoft CAR Repair Services & Auto Mechanic1/6/202117/6/2026
El tema Car Repair Services &amp; Auto Mechanic de WordPress versiones anteriores a 4.0, no saneaba apropiadamente su parámetro search serviceestimatekey antes de devolverlo a la página, conllevando a un problema de tipo Cross-Site Scripting reflejado
ModificadaAlta (8.1)1.0%—Oracle Depot Repair22/4/202117/6/2026
Una vulnerabilidad en el producto Oracle Depot Repair de Oracle E-Business Suite (componente: LOV).&#xa0;Las versiones compatibles que están afectadas son 12.1.1-12.1.3.&#xa0;La vulnerabilidad fácilmente explotable permite a un atacante poco privilegiado con acceso a la red por medio de HTTP comprometer a Oracle Depot…