Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

190 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.56%—Adonesevangelista Online Blood Bank Management System31/7/202417/6/2026
A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated…
AnalizadaMedia (6.9)0.74%—Adonesevangelista Online Blood Bank Management System31/7/202417/6/2026
A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php of the component Admin Login. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The…
AnalizadaMedia (5.3)0.48%—Adonesevangelista Online Blood Bank Management System31/7/202417/6/2026
A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /request.php of the component Send Blood Request Page. The manipulation of the argument Address/bloodgroup leads to cross site scripting. The…
ModificadaMedia (6.9)0.73%—Adonesevangelista Online Blood Bank Management System22/7/202417/6/2026
A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php of the component Login. The manipulation of the argument user/pass leads to sql injection. The attack may be launched remotely. The…
ModificadaCrítica (9.8)1.4%—Unknown-corp Melty Blood Actress Again Current Code28/6/202417/6/2026
Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a client's machine via a crafted packet on TCP port 46318.
AnalizadaMedia (6.9)0.85%—Adonesevangelista Online Blood Bank Management System30/5/202417/6/2026
A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file changepwd.php. The manipulation of the argument useremail leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.69%—Adonesevangelista Online Blood Bank Management System30/5/202417/6/2026
A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file massage.php. The manipulation of the argument bid leads to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaAlta (7.1)0.35%—Bloompixel MAX Addons PRO FOR BricksAI24/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BloomPixel Max Addons Pro for Bricks allows Reflected XSS.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.
AplazadaMedia (6.5)0.44%—Bloompixel MAX Addons PRO FOR BricksAI24/4/202417/6/2026
Missing Authorization vulnerability in BloomPixel Max Addons Pro for Bricks.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.
AplazadaMedia (5.5)0.20%—RedisbloomAI9/4/202417/6/2026
RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the `CF.RESERVE` command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.
AplazadaAlta (7)0.42%—RedisbloomAI9/4/202417/6/2026
RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and…
ModificadaMedia (4.8)0.50%—Phpgurukul Blood Bank & Donor Management System13/1/202417/6/2026
A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.2)0.67%—Phpgurukul Blood Bank & Donor Management System12/1/202417/6/2026
A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.8)0.80%💥 ExploitCode-projects Blood Bank14/11/202317/6/2026
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.
ModificadaMedia (5.5)0.35%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
ModificadaMedia (6.1)0.48%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
ModificadaMedia (6.1)0.47%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.
ModificadaMedia (5.5)0.36%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.
ModificadaMedia (5.5)0.36%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.
ModificadaMedia (6.1)0.47%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.
ModificadaMedia (6.1)0.47%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.
ModificadaMedia (5.5)0.39%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
ModificadaMedia (6.1)0.38%—Projectworlds Online Blood Donation Management System31/10/202317/6/2026
Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the users/member.php response.
ModificadaAlta (8.8)0.25%—Tablooa3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Taboola plugin <= 2.0.1 versions.
ModificadaMedia (5.4)0.50%💥 PoCPhpgurukul Blood Bank & Donor Management System8/9/202317/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.