Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.51% | — | Lerouxyxchire Client Database Management System | 20/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the argument order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (6.9) | 0.48% | — | Lerouxyxchire Client Database Management System | 19/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.49% | — | Lerouxyxchire Client Database Management System | 19/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack may be initiated… | |
| Analizada | Media (6.9) | 0.51% | — | Lerouxyxchire Client Database Management System | 19/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.51% | — | Projectworlds Hospital Database Management System | 16/5/2025 | 17/6/2026 | A vulnerability was found in projectworlds Hospital Database Management System 1.0. It has been classified as critical. This affects an unknown part of the file /medicines_info.php. The manipulation of the argument Med_ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.30% | — | Wpproking Backup Database | 15/5/2025 | 17/6/2026 | The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Crítica (9.8) | 0.42% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload… | |
| Analizada | Crítica (9.8) | 0.42% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 0.76% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 0.67% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. | |
| Aplazada | Media (5.9) | 0.47% | — | Database ToolsetAI | 3/5/2025 | 17/6/2026 | The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in a publicly accessible location. This makes it possible for unauthenticated attackers to extract sensitive data from database backup files. An index file is… | |
| Aplazada | Crítica (9.1) | 1.1% | — | Database ToolsetAI | 24/4/2025 | 17/6/2026 | The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the… | |
| Analizada | Media (5.4) | 0.40% | — | Oracle XML Database | 15/4/2025 | 17/6/2026 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via HTTP to compromise XML Database. Successful attacks… | |
| Aplazada | Alta (8.6) | 0.78% | — | Neoslab Database ToolsetAI | 11/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset database-toolset allows Path Traversal.This issue affects Database Toolset: from n/a through <= 1.8.4. | |
| Aplazada | Media (5.4) | 0.49% | — | TIM Nguyen 1-click Backup Restore DatabaseAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.29% | — | Pepro DEV Group Pepro CF7 DatabaseAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev CF7 Database pepro-cf7-database allows Stored XSS.This issue affects PeproDev CF7 Database: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Custom Database Applications BY CaspioAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Caspio Bridge Custom Database Applications by Caspio custom-database-applications-by-caspio allows DOM-Based XSS.This issue affects Custom Database Applications by Caspio: from n/a through <= 2.1. | |
| Aplazada | Media (4.3) | 0.14% | — | Matthewprice1178 WP Database OptimizerAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in matthewprice1178 WP Database Optimizer wp-database-optimizer allows Cross Site Request Forgery.This issue affects WP Database Optimizer: from n/a through <= 1.2.1.3. | |
| Aplazada | Media (5.9) | 0.23% | — | Matthewprice1178 WP Database OptimizerAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthewprice1178 WP Database Optimizer wp-database-optimizer allows Stored XSS.This issue affects WP Database Optimizer: from n/a through <= 1.2.1.3. | |
| Aplazada | Alta (7.1) | 0.36% | — | Khanhtruong WP Database AuditAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khanhtruong WP Database Audit database-audit allows Reflected XSS.This issue affects WP Database Audit: from n/a through <= 1.0. | |
| Aplazada | Alta (7.2) | 1.0% | — | Database Backup AND Check Tables Automated With SchedulerAI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.59% | — | Database Backup AND Check Tables Automated With Scheduler 2024AI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (6.5) | 0.52% | — | Tamlyn Database SyncAI | 22/1/2025 | 17/6/2026 | Missing Authorization vulnerability in tamlyn Database Sync database-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database Sync: from n/a through <= 0.5.1. |