Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
190 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Bloofoxcms | 11/8/2023 | 17/6/2026 | File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module. | |
| Modificada | Crítica (9.8) | 0.50% | — | Phpscriptpoint Bloodbank | 23/7/2023 | 17/6/2026 | A vulnerability classified as critical has been found in phpscriptpoint BloodBank 1.1. Affected is an unknown function of the file /search of the component POST Parameter Handler. The manipulation of the argument country/city/blood_group_id leads to sql injection. It is possible to launch the attack remotely.… | |
| Modificada | Media (6.1) | 0.36% | — | Phpscriptpoint Bloodbank | 23/7/2023 | 17/6/2026 | A vulnerability was found in phpscriptpoint BloodBank 1.1. It has been rated as problematic. This issue affects some unknown processing of the file page.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235205 was assigned to this vulnerability. NOTE: The… | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | |
| Modificada | Crítica (9.8) | 3.4% | 💥 Exploit | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Bloofoxcms | 14/6/2023 | 9/7/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | |
| Modificada | Crítica (9.8) | 1.0% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit. | |
| Modificada | Alta (8.8) | 0.72% | — | Bloofoxcms | 13/4/2023 | 17/6/2026 | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. | |
| Modificada | Crítica (9.1) | 1.2% | — | Bloofoxcms | 13/4/2023 | 9/7/2026 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | |
| Modificada | Media (6.5) | 1.0% | — | Bloofoxcms | 26/1/2023 | 17/6/2026 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php. | |
| Modificada | Alta (7.8) | 0.40% | — | Bloom Project Bloom | 12/1/2023 | 17/6/2026 | Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1. | |
| Modificada | Media (6.1) | 0.43% | — | Blood Bank Management System Project Blood Bank Management System | 25/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the… | |
| Modificada | Crítica (9.8) | 0.63% | — | Blood Bank Management System Project Blood Bank Management System | 25/12/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The identifier VDB-216773 was… | |
| Modificada | Alta (7.8) | 0.35% | — | Quarkslab Binbloom | 14/12/2022 | 17/6/2026 | Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c. | |
| Modificada | Alta (8.1) | 1.6% | 💥 PoC | Phpgurukul Blood Donor Management System Project Phpgurukul Blood Donor Management System | 25/11/2022 | 17/6/2026 | PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report. | |
| Modificada | Media (4.8) | 0.67% | 💥 PoC | Phpgurukul Blood Donor Management System | 21/11/2022 | 17/6/2026 | Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature. | |
| Modificada | Alta (8.8) | 1.2% | — | Bloodshed Dev-c++ | 23/5/2022 | 17/6/2026 | Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe. | |
| Modificada | Alta (8.8) | 1.3% | — | Bloofoxcms | 26/4/2022 | 17/6/2026 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | |
| Modificada | Crítica (9.8) | 1.4% | — | Bloofoxcms | 24/2/2022 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | |
| Modificada | Media (5.4) | 0.49% | — | Bloofoxcms | 24/2/2022 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php. | |
| Modificada | Baja (2.7) | 0.97% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. | |
| Modificada | Media (5.4) | 0.83% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. |