Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.61% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.43% | — | Razormist Loan Management System | 24/3/2023 | 17/6/2026 | SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Type parameter under the Edit Loan Types module. | |
| Modificada | Crítica (9.8) | 0.89% | — | Razormist Loan Management System | 7/1/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (5.4) | 0.62% | — | Razormist Loan Management System | 14/9/2022 | 17/6/2026 | Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Razormist Loan Management System | 14/9/2022 | 17/6/2026 | Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form. | |
| Modificada | Media (6.1) | 0.67% | — | Cobub Razor | 30/8/2022 | 17/6/2026 | Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel(). | |
| Modificada | Crítica (9.8) | 1.2% | — | Razormist Loan Management System | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Loan Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.87% | — | Razormist Loan Management System | 5/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Loan Management System and classified as critical. This issue affects some unknown processing of the file delete_lplan.php. The manipulation of the argument lplan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts. | |
| Modificada | Media (6.5) | 0.85% | 💥 PoC | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts. | |
| Modificada | Media (4.8) | 0.50% | — | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name. | |
| Modificada | Alta (7.2) | 0.96% | — | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team. | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Razorengine Project Razorengine | 6/3/2022 | 17/6/2026 | In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Analizada | Crítica (9.8) | 1.6% | — | Razormist Complaint Management System | 27/10/2021 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php. | |
| Modificada | Media (5.4) | 0.61% | — | Razormist Employee Management System | 15/6/2021 | 17/6/2026 | A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cobub Razor | 29/3/2019 | 17/6/2026 | Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type. | |
| Modificada | Media (5.4) | 0.66% | — | Razorcms | 31/12/2018 | 17/6/2026 | Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. | |
| Modificada | Media (5.4) | 0.67% | — | Razorcms | 31/12/2018 | 17/6/2026 | HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. | |
| Modificada | Alta (8.8) | 0.61% | — | Razorcms | 5/10/2018 | 17/6/2026 | rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user. | |
| Modificada | Media (5.4) | 0.58% | — | Razorcms | 12/9/2018 | 17/6/2026 | razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. | |
| Modificada | Media (5.4) | 0.58% | — | Razorcms | 12/9/2018 | 17/6/2026 | razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. | |
| Modificada | Crítica (9.8) | 1.9% | — | Puppet Pe-razor-serverPuppet EnterprisePuppet Razor-server | 11/6/2018 | 17/6/2026 | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0. | |
| Modificada | Media (5.3) | 59% | 💥 Exploit | Cobub Razor | 18/3/2018 | 17/6/2026 | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php,… | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Westernbridgegroup Razor | 11/3/2018 | 17/6/2026 | A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Cobub Razor | 11/3/2018 | 17/6/2026 | Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php. |