Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

3077 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.73%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability has been found in SourceCodester Doctors Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/patient.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack can be…
ModificadaAlta (8.8)0.70%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Doctors Appointment System 1.0. Affected is an unknown function of the file /admin/add-new.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely.…
AnalizadaMedia (5.3)0.76%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argument email/oldmail leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (5.3)0.76%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads to sql injection. The attack can be initiated remotely. The…
ModificadaAlta (8.8)0.76%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Doctors Appointment System 1.0. This affects an unknown part of the file create-account.php. The manipulation of the argument newemail leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.73%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been rated as critical. Affected by this issue is the function edoc of the file login.php. The manipulation of the argument usermail leads to sql injection. VDB-221822 is the identifier assigned to this vulnerability.
ModificadaAlta (8.8)0.70%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edoc/doctor/patient.php. The manipulation of the argument search12 leads to sql injection. The attack can be launched remotely. The…
ModificadaCrítica (9.8)0.92%—Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System26/2/202317/6/2026
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be…
ModificadaMedia (6.1)0.78%—Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System26/2/202317/6/2026
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /APR/signup.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The…
ModificadaCrítica (9.8)1.2%—Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql17/2/202317/6/2026
Existe una vulnerabilidad de inyección SQL en Projectworlds Online Doctor Appointment Booking System, que permite a los atacantes obtener información confidencial a través del parámetro q en el endpoint getuser.php.
ModificadaAlta (7.8)0.21%—Infoblox Bloxone Endpoint17/2/202317/6/2026
Infoblox BloxOne Endpoint para Windows hasta 2.2.7 permite la inyección de DLL que puede resultar en una escalada de privilegios locales.
ModificadaMedia (5.3)0.15%—Intel Endpoint Management Assistant16/2/202317/6/2026
Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaAlta (8.8)1.1%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server14/2/202319/8/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
ModificadaCrítica (9.8)85%💥 PoCMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+414/2/202319/8/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (8.8)0.94%—Pinpoint Booking System13/2/202317/6/2026
El complemento Pinpoint Booking System de WordPress anterior a 2.9.9.2.9 no valida ni escapa uno de sus atributos de código corto antes de usarlo en una declaración SQL, lo que podría permitir a cualquier usuario autenticado, como un suscriptor, realizar ataques de inyección SQL.
ModificadaAlta (7.8)0.26%—Elastic EndgameElastic Endpoint Security8/2/202317/6/2026
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
ModificadaMedia (5.9)16%💥 PoCOpensslStormshield Endpoint SecurityStormshield SslvpnStormshield Network Security8/2/202317/6/2026
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The…
ModificadaAlta (7.5)0.94%—Sailpoint Identityiq31/1/202317/6/2026
IdentityIQ 8.3 y todos los niveles de parche 8.3 anteriores a 8.3p2, IdentityIQ 8.2 y todos los niveles de parche 8.2 anteriores a 8.2p5, IdentityIQ 8.1 y todos los niveles de parche 8.1 anteriores a 8.1p7, IdentityIQ 8.0 y todos los niveles de parche 8.0 anteriores a 8.0p6 permiten el acceso a archivos arbitrarios en…
ModificadaMedia (6.5)0.39%—Sailpoint Identityiq31/1/202317/6/2026
IdentityIQ 8.3 y todos los niveles de parche 8.3 anteriores a 8.3p2, IdentityIQ 8.2 y todos los niveles de parche 8.2 anteriores a 8.2p5, IdentityIQ 8.1 y todos los niveles de parche 8.1 anteriores a 8.1p7, IdentityIQ 8.0 y todos los niveles de parche 8.0 anteriores a 8.0p6, y todos Las versiones anteriores permiten a…
ModificadaMedia (6.1)0.48%—Phpgurukul Doctor Appointment Management System26/1/202317/6/2026
phpgurukul Doctor Appointment Management System V 1.0.0 es vulnerable a Cross Site Scripting (XSS) a través de searchdata=.
ModificadaMedia (6.1)0.52%—Phpgurukul Doctor Appointment Management System26/1/202317/6/2026
Una vulnerabilidad de cross site scripting (XSS) en Doctor Appointment Management System v1.0.0 permite a los atacantes ejecutar scripts web arbitrarios o HTML a través de un payload manipulado inyectado en la función de búsqueda.
ModificadaAlta (7.8)0.26%—Elastic Endpoint Security26/1/202317/6/2026
Se descubrió un problema en la función de reversión de Elastic Endpoint Security para Windows, que podría permitir a los usuarios sin privilegios elevar sus privilegios a los de la cuenta LocalSystem.
ModificadaAlta (7.8)0.24%—Elastic EndgameElastic Endpoint Security26/1/202317/6/2026
Se descubrió un problema en la función de cuarentena de Elastic Endpoint Security y Elastic Endgame para Windows, que podría permitir a los usuarios sin privilegios elevar sus permisos a los de la cuenta LocalSystem.
ModificadaMedia (5.4)0.47%—Easy-appointments Easy Appointments23/1/202317/6/2026
El complemento Easy Appointments de WordPress anterior a 3.11.2 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían usarse contra…
ModificadaAlta (7.8)0.23%—Cybereason Endpoint Detection AND Response20/1/20239/7/2026
Cybereason EDR versión 19.1.282 y superior, 19.2.182 y superior, 20.1.343 y superior, y 20.2.X y superior tienen una vulnerabilidad de secuestro de DLL, que podría permitir a un atacante local ejecutar código con privilegios elevados.