Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
3004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely. | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Baja (0.9) | 0.11% | — | Meesho Online Shopping APPAI | 3/8/2026 | 12/8/2026 | A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The… | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Exchange Online | 24/7/2026 | 29/7/2026 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Online ClassroomAI | 23/7/2026 | 24/7/2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (4.3) | 0.36% | — | Bizimhesap Information Systems Industry AND Trade INC Online Pre-accounting SoftwareAI | 23/7/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | |
| Aplazada | Media (6.5) | 0.36% | 💥 PoC | Universe Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI | 22/7/2026 | 5/8/2026 | Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Customers Online | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Customers Online | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Customers Online | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Examination SystemAI | 19/7/2026 | 22/7/2026 | A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (5.3) | 0.36% | — | Rafymrx Toko-online-rotiAI | 16/7/2026 | 16/7/2026 | A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out remotely. This product adopts a rolling… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |