Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

126 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.48%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
ModificadaMedia (6.1)0.47%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.
ModificadaMedia (5.5)0.36%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.
ModificadaMedia (5.5)0.36%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.
ModificadaMedia (6.1)0.47%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.
ModificadaMedia (6.1)0.47%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.
ModificadaMedia (5.5)0.39%💥 PoCCode-projects Blood Bank13/11/202317/6/2026
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
ModificadaMedia (6.1)0.38%—Projectworlds Online Blood Donation Management System31/10/202317/6/2026
Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the users/member.php response.
ModificadaMedia (5.4)0.50%💥 PoCPhpgurukul Blood Bank & Donor Management System8/9/202317/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
ModificadaCrítica (9.8)0.50%—Phpscriptpoint Bloodbank23/7/202317/6/2026
A vulnerability classified as critical has been found in phpscriptpoint BloodBank 1.1. Affected is an unknown function of the file /search of the component POST Parameter Handler. The manipulation of the argument country/city/blood_group_id leads to sql injection. It is possible to launch the attack remotely.…
ModificadaMedia (6.1)0.36%—Phpscriptpoint Bloodbank23/7/202317/6/2026
A vulnerability was found in phpscriptpoint BloodBank 1.1. It has been rated as problematic. This issue affects some unknown processing of the file page.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235205 was assigned to this vulnerability. NOTE: The…
ModificadaMedia (6.1)0.43%—Blood Bank Management System Project Blood Bank Management System25/12/202217/6/2026
A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the…
ModificadaCrítica (9.8)0.63%—Blood Bank Management System Project Blood Bank Management System25/12/202217/6/2026
A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The identifier VDB-216773 was…
ModificadaAlta (8.1)1.6%💥 PoCPhpgurukul Blood Donor Management System Project Phpgurukul Blood Donor Management System25/11/202217/6/2026
PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.
ModificadaMedia (4.8)0.67%💥 PoCPhpgurukul Blood Donor Management System21/11/202217/6/2026
Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.
ModificadaAlta (8.8)1.2%—Bloodshed Dev-c++23/5/202217/6/2026
Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe.
ModificadaCrítica (9.6)2.7%—Bloodhound Project Bloodhound19/2/202117/6/2026
components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.
ModificadaCrítica (9.8)2.7%—Bloodx Project Bloodx2/12/202017/6/2026
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
ModificadaAlta (8.8)2.0%—Bloodhound Project Bloodhound27/8/201917/6/2026
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing…
ModificadaMedia (6.5)1.4%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely…
ModificadaAlta (7.1)1.6%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and…
ModificadaMedia (5.9)2.0%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi…
ModificadaMedia (5.4)0.27%—Bloodjournal Blood20/10/201417/6/2026
The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)7.0%💥 ExploitBloodshed Software Dev-c++31/1/200716/6/2026
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.
ModificadaBaja (2.1)1.9%💥 ExploitFreeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+731/12/200416/6/2026
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
Orbitaley — Vulnerabilidades