Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

121 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.61%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaMedia (5.4)0.43%—Razormist Loan Management System24/3/202317/6/2026
SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Type parameter under the Edit Loan Types module.
ModificadaCrítica (9.8)0.89%—Razormist Loan Management System7/1/202317/6/2026
A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (5.4)0.62%—Razormist Loan Management System14/9/202217/6/2026
Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
ModificadaCrítica (9.8)1.2%—Razormist Loan Management System14/9/202217/6/2026
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
ModificadaMedia (6.1)0.67%—Cobub Razor30/8/202217/6/2026
Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().
ModificadaCrítica (9.8)1.2%—Razormist Loan Management System11/8/202217/6/2026
A vulnerability was found in SourceCodester Loan Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.87%—Razormist Loan Management System5/8/202217/6/2026
A vulnerability was found in SourceCodester Loan Management System and classified as critical. This issue affects some unknown processing of the file delete_lplan.php. The manipulation of the argument lplan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
ModificadaAlta (7.5)1.4%💥 PoCRazormist Online Discussion Forum Site16/6/202217/6/2026
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
ModificadaMedia (6.5)0.85%💥 PoCRazormist Online Discussion Forum Site16/6/202217/6/2026
An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.
ModificadaMedia (4.8)0.50%—Razormist Online Discussion Forum Site16/6/202217/6/2026
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
ModificadaAlta (7.2)0.96%—Razormist Online Discussion Forum Site16/6/202217/6/2026
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
ModificadaCrítica (9.8)1.9%💥 PoCRazorengine Project Razorengine6/3/202217/6/2026
In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer
AnalizadaCrítica (9.8)1.6%—Razormist Complaint Management System27/10/202117/6/2026
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
ModificadaMedia (5.4)0.61%—Razormist Employee Management System15/6/202117/6/2026
A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.
ModificadaCrítica (9.8)1.8%—Cobub Razor29/3/201917/6/2026
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.
ModificadaMedia (5.4)0.66%—Razorcms31/12/201817/6/2026
Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
ModificadaMedia (5.4)0.67%—Razorcms31/12/201817/6/2026
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
ModificadaAlta (8.8)0.61%—Razorcms5/10/201817/6/2026
rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.
ModificadaMedia (5.4)0.58%—Razorcms12/9/201817/6/2026
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
ModificadaMedia (5.4)0.58%—Razorcms12/9/201817/6/2026
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
ModificadaCrítica (9.8)1.9%—Puppet Pe-razor-serverPuppet EnterprisePuppet Razor-server11/6/201817/6/2026
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0.
ModificadaMedia (5.3)59%💥 ExploitCobub Razor18/3/201817/6/2026
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php,…
ModificadaCrítica (9.8)22%💥 ExploitWesternbridgegroup Razor11/3/201817/6/2026
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.
ModificadaAlta (7.5)13%💥 ExploitCobub Razor11/3/201817/6/2026
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php.
Orbitaley — Vulnerabilidades