Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
23.906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online Music SiteAI | 28/4/2026 | 17/6/2026 | A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Media (5.3) | 0.53% | — | Saasproject Booking PackageAI | 28/4/2026 | 17/6/2026 | The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the… | |
| Aplazada | Baja (2.1) | 0.32% | 💥 PoC | Code-projects Coaching Management SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (2) | 0.33% | 💥 PoC | Code-projects Coaching Management SystemAI | 28/4/2026 | 24/7/2026 | Se determinó una vulnerabilidad en code-projects Coaching Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /cims/modules/student/complaint.PHP del componente Complaint Form Page. Esta manipulación del argumento Complaint causa cross site scripting. El ataque puede… | |
| Aplazada | Baja (2.1) | 0.37% | — | 1000projects Portfolio Management System MCAAI | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public… | |
| Aplazada | Baja (2.1) | 0.32% | — | 1000projects Portfolio Management System MCAAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.1) | 0.30% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and HTM file uploads. Authenticated attackers can upload HTML files containing arbitrary JavaScript through the image upload or… | |
| Aplazada | Media (5.1) | 0.32% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only detecting specific patterns while returning unsanitized strings without output encoding. Attackers can inject malicious… | |
| Aplazada | Alta (7.1) | 0.79% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequences ../ into the… | |
| Aplazada | Alta (7.1) | 0.54% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access controls by directly… | |
| Aplazada | Alta (8.7) | 1.6% | — | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit… | |
| Aplazada | Crítica (9.3) | 0.66% | 💥 PoC | ProjeqtorAI | 27/4/2026 | 17/6/2026 | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the… | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.63% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.48% | — | Code-projects Invoice SystemAILaravelAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.22% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Baja (2.1) | 0.35% | — | Code-projects Invoice SystemAILaravelAI | 27/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and… |