Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2771▲ 6 respecto a la semana anterior
Críticas / altas1285▼ 246 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.38% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerabilidad en el producto Oracle Complex Maintenance, Repair and Overhaul de Oracle E-Business Suite (componente: LOV). Las versiones compatibles que se ven afectadas son 12.2.3-12.2.13. Una vulnerabilidad fácilmente explotable permite que un atacante no autenticado con acceso a la red a través de HTTP comprometa… | |
| Modificada | Alta (7.1) | 0.16% | — | Dell Pair | 24/1/2024 | 17/6/2026 | La versión de Dell Pair Installer anterior a la 1.2.1 contiene una vulnerabilidad de elevación de privilegios. Un usuario con privilegios bajos y acceso local al sistema podría explotar esta vulnerabilidad para eliminar archivos arbitrarios y provocar una denegación de servicio. | |
| Modificada | Media (6.1) | 0.17% | — | Oracle Complex Maintenance, Repair, AND Overhaul | 16/1/2024 | 17/6/2026 | Vulnerabilidad en el producto Oracle Complex Maintenance, Repair and Overhaul de Oracle Supply Chain (componente: LOV). Las versiones compatibles que se ven afectadas son 11.5, 12.1 y 12.2. Una vulnerabilidad fácilmente explotable permite que un atacante no autenticado con acceso a la red a través de HTTP comprometa… | |
| Modificada | Alta (8.8) | 0.26% | — | Whereyoursolutionis FIX MY Feed RSS Repair | 17/12/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Innovative Solutions Fix My Feed RSS Repair. Este problema afecta a Fix My Feed RSS Repair: desde n/a hasta 1.4. | |
| Modificada | Media (6.1) | 0.36% | — | Oretnom23 AC Repair AND Services System | 17/9/2023 | 17/6/2026 | Una vulnerabilidad fue encontrada en SourceCodester AC Repair and Services System 1.0 y clasificada como problemática. Una función desconocida del archivo admin/?page=system_info/contact_information es afectada por esta vulnerabilidad. La manipulación del argumento telephone/mobile/address conduce a un Cross-Site… | |
| Modificada | Crítica (9.8) | 0.50% | — | Oretnom23 AC Repair AND Services System | 15/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_inquiry of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql… | |
| Modificada | Crítica (9.8) | 0.54% | — | Oretnom23 AC Repair AND Services System | 13/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated… | |
| Modificada | Media (6.1) | 0.39% | — | Oretnom23 AC Repair AND Services System | 13/7/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Oretnom23 AC Repair AND Services System | 13/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the… | |
| Modificada | Crítica (9.8) | 0.54% | — | Oretnom23 AC Repair AND Services System | 13/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be… | |
| Modificada | Crítica (9.8) | 0.49% | — | Oretnom23 AC Repair AND Services System | 11/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue affects some unknown processing of the file Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated… | |
| Modificada | Alta (8.8) | 0.26% | — | 984.ru FOR THE Visually Impaired | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 984.Ru For the visually impaired plugin <= 0.58 versions. | |
| Modificada | Crítica (9.8) | 0.94% | — | Oretnom23 AC Repair AND Services System | 11/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file /classes/Master.php?f=delete_service. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.63% | — | Oretnom23 AC Repair AND Services System | 29/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bookings/manage_booking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Media (6.5) | 0.53% | — | Oretnom23 AC Repair AND Services System | 29/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.63% | — | Oretnom23 AC Repair AND Services System | 28/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_inquiry.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.63% | — | Oretnom23 AC Repair AND Services System | 28/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/bookings/view_booking.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.63% | — | Oretnom23 AC Repair AND Services System | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. This affects an unknown part of the file /admin/services/view_service.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.63% | — | Oretnom23 AC Repair AND Services System | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. Affected by this issue is some unknown functionality of the file services/view.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Alta (7.8) | 0.43% | — | Wondershare Repairit | 4/4/2023 | 17/6/2026 | An issue found in Wondershare Technology Co.,Ltd Repairit v.3.5.4 allows a remote attacker to execute arbitrary commands via the repairit_setup_full5913.exe file. | |
| Modificada | Alta (7.8) | 0.51% | 💥 PoC | Outbyte PC Repair | 7/9/2022 | 29/7/2026 | El archivo de Instalación de Outbyte PC Repair versión 1.7.112.7856, es vulnerable a un secuestro de Dll. El archivo iertutil.dll falta, por lo que un atacante puede usar una dll maliciosa con el mismo nombre y puede conseguir privilegios de administrador | |
| Modificada | Crítica (9.8) | 1.6% | — | Computer AND Mobile Repair Shop Management System Project Computer AND Mobile Repair Shop Management System | 20/1/2022 | 17/6/2026 | Se presenta una vulnerabilidad de inyección SQL en Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) versión 1.0, por medio del parámetro code en la aplicación del nodo /rsms/ | |
| Modificada | Crítica (9.1) | 3.1% | 💥 PoC | Keypair Project Keypair | 11/10/2021 | 17/6/2026 | keypair es un generador de claves RSA PEM escrito en javascript. keypair implementa un montón de primitivas criptográficas por sí mismo o tomando prestado de otras bibliotecas cuando es posible, incluyendo node-forge. Se detectó un problema en el que esta biblioteca genera claves RSA idénticas a las usadas en SSH.… | |
| Modificada | Media (6.1) | 3.9% | 💥 Exploit | Smartdatasoft CAR Repair Services & Auto Mechanic | 1/6/2021 | 17/6/2026 | El tema Car Repair Services & Auto Mechanic de WordPress versiones anteriores a 4.0, no saneaba apropiadamente su parámetro search serviceestimatekey antes de devolverlo a la página, conllevando a un problema de tipo Cross-Site Scripting reflejado | |
| Modificada | Alta (8.1) | 1.0% | — | Oracle Depot Repair | 22/4/2021 | 17/6/2026 | Una vulnerabilidad en el producto Oracle Depot Repair de Oracle E-Business Suite (componente: LOV). Las versiones compatibles que están afectadas son 12.1.1-12.1.3. La vulnerabilidad fácilmente explotable permite a un atacante poco privilegiado con acceso a la red por medio de HTTP comprometer a Oracle Depot… |