Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.48% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters. | |
| Modificada | Media (6.1) | 0.47% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter. | |
| Modificada | Media (5.5) | 0.36% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter. | |
| Modificada | Media (5.5) | 0.36% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters. | |
| Modificada | Media (6.1) | 0.47% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL. | |
| Modificada | Media (6.1) | 0.47% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL. | |
| Modificada | Media (5.5) | 0.39% | 💥 PoC | Code-projects Blood Bank | 13/11/2023 | 17/6/2026 | SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters. | |
| Modificada | Media (6.1) | 0.38% | — | Projectworlds Online Blood Donation Management System | 31/10/2023 | 17/6/2026 | Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the users/member.php response. | |
| Modificada | Media (5.4) | 0.50% | 💥 PoC | Phpgurukul Blood Bank & Donor Management System | 8/9/2023 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters. | |
| Modificada | Crítica (9.8) | 0.50% | — | Phpscriptpoint Bloodbank | 23/7/2023 | 17/6/2026 | A vulnerability classified as critical has been found in phpscriptpoint BloodBank 1.1. Affected is an unknown function of the file /search of the component POST Parameter Handler. The manipulation of the argument country/city/blood_group_id leads to sql injection. It is possible to launch the attack remotely.… | |
| Modificada | Media (6.1) | 0.36% | — | Phpscriptpoint Bloodbank | 23/7/2023 | 17/6/2026 | A vulnerability was found in phpscriptpoint BloodBank 1.1. It has been rated as problematic. This issue affects some unknown processing of the file page.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235205 was assigned to this vulnerability. NOTE: The… | |
| Modificada | Media (6.1) | 0.43% | — | Blood Bank Management System Project Blood Bank Management System | 25/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the… | |
| Modificada | Crítica (9.8) | 0.63% | — | Blood Bank Management System Project Blood Bank Management System | 25/12/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The identifier VDB-216773 was… | |
| Modificada | Alta (8.1) | 1.6% | 💥 PoC | Phpgurukul Blood Donor Management System Project Phpgurukul Blood Donor Management System | 25/11/2022 | 17/6/2026 | PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report. | |
| Modificada | Media (4.8) | 0.67% | 💥 PoC | Phpgurukul Blood Donor Management System | 21/11/2022 | 17/6/2026 | Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature. | |
| Modificada | Alta (8.8) | 1.2% | — | Bloodshed Dev-c++ | 23/5/2022 | 17/6/2026 | Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe. | |
| Modificada | Crítica (9.6) | 2.7% | — | Bloodhound Project Bloodhound | 19/2/2021 | 17/6/2026 | components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter. | |
| Modificada | Crítica (9.8) | 2.7% | — | Bloodx Project Bloodx | 2/12/2020 | 17/6/2026 | SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. | |
| Modificada | Alta (8.8) | 2.0% | — | Bloodhound Project Bloodhound | 27/8/2019 | 17/6/2026 | components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing… | |
| Modificada | Media (6.5) | 1.4% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely… | |
| Modificada | Alta (7.1) | 1.6% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and… | |
| Modificada | Media (5.9) | 2.0% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi… | |
| Modificada | Media (5.4) | 0.27% | — | Bloodjournal Blood | 20/10/2014 | 17/6/2026 | The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 7.0% | 💥 Exploit | Bloodshed Software Dev-c++ | 31/1/2007 | 16/6/2026 | Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file. | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. |