Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.33% | — | Expresstech Quiz AND Survey Master | 3/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (5.3) | 0.55% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_question.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.55% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_result.php. The manipulation of the argument qid leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.62% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Realtime Quiz System 1.0. Affected is an unknown function of the file /print_quiz_records.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.60% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Realtime Quiz System 1.0. This issue affects some unknown processing of the file /my_quiz_result.php. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.55% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Realtime Quiz System 1.0. This vulnerability affects unknown code of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.51% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=load_answered. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.51% | — | Oretnom23 Simple Realtime Quiz System | 2/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /quiz_board.php. The manipulation of the argument quiz leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.51% | — | Oretnom23 Simple Realtime Quiz System | 1/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /quiz_view.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 Simple Realtime Quiz System | 1/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_quiz.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.64% | — | Oretnom23 Simple Realtime Quiz System | 1/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.40% | — | Oretnom23 Simple Realtime Quiz System | 1/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.35% | — | Oretnom23 Simple Realtime Quiz System | 1/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.8) | 0.26% | — | Kibokolabs Chained Quiz | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Chained Quiz allows Stored XSS.This issue affects Chained Quiz: from n/a through 1.3.2.8. | |
| Modificada | Media (5.4) | 0.39% | — | Kibokolabs Watu Quiz | 12/7/2024 | 17/6/2026 | The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.38% | — | Expresstech Quiz AND Survey Master | 11/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.59% | — | Expresstech Quiz AND Survey Master | 2/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role | |
| Analizada | Media (5.5) | 0.35% | — | Expresstech Quiz AND Survey Master | 1/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Ays-pro Quiz Maker | 25/6/2024 | 17/6/2026 | The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (5.3) | 0.31% | — | Expresstech Quiz AND Survey Master | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16. | |
| Modificada | Media (6.5) | 0.48% | — | Expresstech Quiz AND Survey Master | 7/6/2024 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (5.4) | 0.36% | — | Ari-soft ARI Stream QuizAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2. | |
| Analizada | Media (6.1) | 0.41% | — | Techkshetrainfo Savsoft Quiz | 3/5/2024 | 17/6/2026 | Savsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter. | |
| Analizada | Media (4.8) | 0.52% | — | Techkshetrainfo Savsoft Quiz | 27/4/2024 | 17/6/2026 | A vulnerability was found in Techkshetra Info Solutions Savsoft Quiz 6.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /public/index.php/Qbank/editCategory of the component Category Page. The manipulation of the argument category_name with the input… | |
| Modificada | Media (5.3) | 0.40% | — | Ays-pro Quiz Maker | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4. |