Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.48% | — | Mayurik PET Grooming Management Software | 18/9/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument inv_no/insta_amt causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed… | |
| Analizada | Media (5.5) | 0.42% | — | Mayurik PET Grooming Management Software | 17/9/2025 | 25/9/2026 | A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown processing of the file /admin/search_product.php. Such manipulation of the argument group_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be… | |
| Analizada | Baja (2.1) | 0.39% | — | Mayurik PET Grooming Management Software | 15/9/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file /admin/ajax_represent.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.39% | — | Mayurik PET Grooming Management Software | 15/9/2025 | 17/6/2026 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/barcode.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.39% | — | Mayurik PET Grooming Management Software | 15/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services results in sql injection. The attack can be launched remotely. The exploit is now public… | |
| Analizada | Baja (2.1) | 0.42% | — | Mayurik PET Grooming Management Software | 15/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/seo_setting.php of the component Setting Handler. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.42% | — | Mayurik PET Grooming Management Software | 15/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/operation/user.php. Executing manipulation of the argument website_image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.47% | — | Mayurik PET Grooming Management Software | 14/9/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_role.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly… | |
| Analizada | Alta (7.8) | 0.42% | — | Microsoft Xbox Gaming Services | 9/9/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. | |
| Analizada | Baja (2) | 0.40% | — | Mayurik PET Grooming Management Software | 8/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Such manipulation of the argument product_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2.1) | 0.36% | — | Mayurik PET Grooming Management Software | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been released to the public and may be… | |
| Analizada | Baja (2.1) | 0.43% | — | Mayurik PET Grooming Management Software | 8/9/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. Executing manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2) | 0.46% | — | Mayurik PET Grooming Management Software | 8/9/2025 | 17/6/2026 | A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument website_image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Alta (7.2) | 0.47% | — | Rubel Miah Aitasi Coming SoonAI | 5/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon aitasi-coming-soon allows Object Injection.This issue affects Aitasi Coming Soon: from n/a through <= 2.0.2. | |
| Analizada | Alta (7.5) | 0.78% | — | Microsoft Xbox Gaming Services | 4/9/2025 | 30/9/2026 | Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.39% | — | Anisha Online Movie Streaming | 1/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-control.php. The manipulation of the argument ID leads to missing authorization. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.41% | — | Anisha Online Movie Streaming | 1/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the file /admin.php. The manipulation of the argument ID leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (8.8) | 0.76% | — | Mingyu Security GatewayAI | 17/7/2025 | 17/6/2026 | Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/fw_security.mds. | |
| Aplazada | Alta (8.7) | 0.85% | — | Hikvision Streaming Media Management ServerAI | 1/7/2025 | 17/6/2026 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory… | |
| Aplazada | Media (5.9) | 0.25% | — | Robert Cummings Quick FaviconAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Cummings Quick Favicon quick-favicon allows Stored XSS.This issue affects Quick Favicon: from n/a through <= 0.22.8. | |
| Modificada | Alta (8.8) | 0.18% | — | Videowhisper Live Streaming Integration | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.This issue affects Broadcast Live Video: from n/a through <= 6.2.4. | |
| Aplazada | Media (5.4) | 0.13% | — | Endurance Gaming ModeAI | 13/5/2025 | 17/6/2026 | Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.33% | — | Kefaming MayiAI | 6/5/2025 | 17/6/2026 | A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file app/tools/controller/File.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.78% | — | Mingsoft Mcms | 21/4/2025 | 5/7/2026 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Aplazada | Alta (7.1) | 0.29% | — | Mapro Collins Coming Soon CountdownAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapro Collins Coming Soon Countdown coming-soon-countdown allows Reflected XSS.This issue affects Coming Soon Countdown: from n/a through <= 2.2. |