Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
3004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 25/8/2026 | A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 21/8/2026 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 21/8/2026 | A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB Portal SystemAI | 19/8/2026 | 25/8/2026 | A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Customers Online | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Customer Tab). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of… | |
| Aplazada | Alta (7.5) | 0.39% | — | Online Contact WidgetAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Shopping SystemAI | 17/8/2026 | 20/8/2026 | A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could… | |
| Aplazada | Alta (7.2) | 0.42% | — | Platnosci Online Blue MediaAI | 16/8/2026 | 20/8/2026 | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Food Order SystemAI | 15/8/2026 | 20/8/2026 | A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online Food Order SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.53% | — | Sourcecodester Online Clothing StoreAI | 15/8/2026 | 20/8/2026 | A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.2) | 0.40% | — | Vcita Online Booking Scheduling CalendarAI | 15/8/2026 | 20/8/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.1) | 0.25% | — | Zaytech Smart Online Order FOR CloverAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | |
| Aplazada | Media (5.5) | 0.56% | — | Sourcecodester Online Clothing StoreAIAdobe DreamweaverAI | 7/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit… | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Sharepoint Online | 7/8/2026 | 7/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.35% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely. |