Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
2111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.32% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 18/4/2023 | 17/6/2026 | A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account. | |
| Modificada | Alta (7.5) | 0.60% | — | Campcodes Video Sharing Website Project Campcodes Video Sharing Website | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin_class.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.79% | — | Campcodes Video Sharing Website Project Campcodes Video Sharing Website | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been classified as critical. This affects an unknown part of the file watch.php. The manipulation of the argument code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.5) | 0.65% | — | Campcodes Video Sharing Website Project Campcodes Video Sharing Website | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file upload.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.5) | 0.66% | — | Campcodes Video Sharing Website Project Campcodes Video Sharing Website | 14/4/2023 | 17/6/2026 | A vulnerability has been found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file signup.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.98% | — | Online Pizza Ordering Project Online Pizza Ordering | 14/4/2023 | 17/6/2026 | Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | |
| Modificada | Media (6.5) | 0.66% | — | Vmware Spring Session | 13/4/2023 | 17/6/2026 | In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver. | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Framework | 13/4/2023 | 17/6/2026 | In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Idnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter | 12/4/2023 | 17/6/2026 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). | |
| Modificada | Crítica (9.8) | 0.74% | — | Phpgurukul BP Monitoring Management System | 8/4/2023 | 17/6/2026 | A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file password-recovery.php of the component Password Recovery. The manipulation of the argument emailid/contactno leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 0.71% | — | Phpgurukul BP Monitoring Management System | 8/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file change-password.php of the component Change Password Handler. The manipulation of the argument password leads to sql injection. It is possible to launch the attack… | |
| Modificada | Media (6.1) | 0.56% | — | Phpgurukul BP Monitoring Management System | 8/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file add-family-member.php of the component Add New Family Member Handler. The manipulation of the argument Member Name leads to cross site… | |
| Modificada | Media (6.5) | 0.63% | — | Phpgurukul BP Monitoring Management System | 7/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack… | |
| Modificada | Media (6.1) | 0.55% | — | Gadget Works Online Ordering System Project Gadget Works Online Ordering System | 2/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/products/index.php of the component GET Parameter Handler. The manipulation of the argument view with the input… | |
| Modificada | Alta (7.5) | 3.5% | 💥 PoC | Vmware Spring Framework | 27/3/2023 | 17/6/2026 | Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass. | |
| Modificada | Media (6.5) | 0.97% | — | Vmware Spring Framework | 23/3/2023 | 17/6/2026 | In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | |
| Modificada | Media (5.5) | 0.22% | — | Vmware Spring Cloud ConfigVmware Spring Cloud VaultVmware Spring Vault | 23/3/2023 | 17/6/2026 | In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token. | |
| Modificada | Media (6.1) | 0.56% | — | Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System | 18/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this issue is some unknown functionality of the file modules/balance/index.php?view=balancelist of the component POST Parameter Handler. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 0.74% | — | Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument un leads to sql injection. The attack can be… | |
| Modificada | Crítica (9.8) | 0.97% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 17/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to initiate the attack… | |
| Modificada | Alta (8.1) | 0.57% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file admin/ajax.php?action=login2 of the component Login Page. The manipulation of the argument email with the input abc%40qq.com' AND (SELECT 9110 FROM… | |
| Modificada | Alta (7.2) | 0.87% | — | Gadget Works Online Ordering System Project Gadget Works Online Ordering System | 16/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file admin/products/controller.php?action=add of the component Products Handler. The manipulation of the argument filename leads to unrestricted upload. It is… | |
| Modificada | Crítica (9.8) | 0.59% | — | Oretnom23 Online Food Ordering System | 16/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be… | |
| Modificada | Media (6.1) | 0.58% | — | Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System | 15/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file cashconfirm.php of the component POST Parameter Handler. The manipulation of the argument transactioncode leads to cross… | |
| Modificada | Crítica (9.8) | 0.76% | — | Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System | 15/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to sql injection. The attack may… |