Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3075▲ 488 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
23.914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.61% | — | ProjectlistAI | 25/11/2025 | 17/6/2026 | The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 0.3.0. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make… | |
| Aplazada | Media (4.9) | 0.31% | — | ProjectlistAI | 25/11/2025 | 17/6/2026 | The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Analizada | Baja (2.1) | 0.31% | — | Code-projects Library System | 24/11/2025 | 8/10/2026 | Se determinó una vulnerabilidad en code-projects Library System 1.0. Se ve afectada una función desconocida del archivo /mail.php. Esta manipulación del argumento ID causa inyección SQL. El ataque puede iniciarse remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado. | |
| Analizada | Baja (2.1) | 0.31% | — | Code-projects Library System | 24/11/2025 | 8/10/2026 | Una vulnerabilidad fue encontrada en code-projects Library System 1.0. Esto impacta una función desconocida del archivo /return.php. La manipulación del argumento ID resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit ha sido hecho público y podría ser usado. | |
| Analizada | Media (5.5) | 0.39% | — | Code-projects Library System | 24/11/2025 | 8/10/2026 | Una vulnerabilidad ha sido encontrada en code-projects Library System 1.0. Esto afecta una función desconocida del archivo /index.php del componente Login. La manipulación del argumento Username conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado al público y puede ser… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 23/11/2025 | 8/10/2026 | Una falla de seguridad ha sido descubierta en projectworlds puede pasar cargas útiles maliciosas hasta 1.0. Esta vulnerabilidad afecta código desconocido del archivo /add_book.php. La manipulación del argumento image resulta en subida irrestricta. El ataque puede ser ejecutado remotamente. El exploit ha sido publicado… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Advanced Library Management System | 23/11/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en projectworlds Advanced Biblioteca Management System 1.0. Esto afecta una parte desconocida del archivo /delete_admin.php. La manipulación del argumento admin_id conduce a inyección SQL. La explotación remota del ataque es posible. El exploit está disponible públicamente y podría… | |
| Analizada | Media (6.1) | 0.21% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('subject', 'server', 'database', 'queryid') without proper validation or access control checks.… | |
| Analizada | Media (6.5) | 0.29% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery function without proper sanitization. An authenticated attacker can exploit this vulnerability to execute arbitrary SQL… | |
| Analizada | Media (6.5) | 0.27% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any sanitization or parameterization via $data->conn->Execute($_REQUEST['query']). An authenticated attacker can… | |
| Analizada | Media (6.1) | 0.23% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper encoding or sanitization in multiple locations including sequences.php, indexes.php, admin.php, and other… | |
| Aplazada | Media (4.8) | 0.26% | — | Public Knowledge Project OMPAIPublic Knowledge Project OJSAI | 20/11/2025 | 17/6/2026 | A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross… | |
| Analizada | Media (5.5) | 0.40% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2) | 0.24% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.40% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.1) | 0.23% | — | Easyimages2.0 Project Easyimages2.0 | 19/11/2025 | 17/6/2026 | A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. | |
| Analizada | Media (6.1) | 0.23% | — | Learnwithfair Php-ecommerce-project | 19/11/2025 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the id parameter. | |
| Analizada | Baja (3.5) | 0.17% | — | Simple Multi Step Form Project Simple Multi Step Form | 18/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Site Scripting (XSS).This issue affects Simple multi step form: from 0.0.0 before 2.0.0. | |
| Analizada | Media (5.4) | 0.20% | — | Email TFA Project Email TFA | 18/11/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6. | |
| Analizada | Media (6.5) | 0.86% | — | MCP Server FOR Data Exploration Project MCP Server FOR Data Exploration | 18/11/2025 | 17/6/2026 | A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() function (src/mcp_server_ds/server.py:108). The function uses Python's exec() to execute user-supplied scripts but fails to restrict the __builtins__ dictionary in the… | |
| Aplazada | Media (6.1) | 0.14% | — | Project Honey POT Spam TrapAI | 18/11/2025 | 17/6/2026 | The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the printAdminPage() function. This makes it possible for unauthenticated attackers to update settings and inject… | |
| Analizada | Baja (2.1) | 0.31% | — | 1000projects Design & Development OF Student Database Management System | 17/11/2025 | 7/10/2026 | Una vulnerabilidad fue detectada en 1000projects Design & Development of Student Database Management System 1.0. Afecta a una función desconocida del archivo /TeacherLogin/Academics/SubjectDetails.php. La manipulación del argumento SubCode resulta en inyección SQL. El ataque puede realizarse de forma remota. El… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | Una vulnerabilidad ha sido encontrada en projectworlds Advanced Library Management System 1.0. Afecta a una función desconocida del archivo /borrowed_book_search.php. Dicha manipulación del argumento datefrom/dateto conduce a inyección SQL. El ataque puede lanzarse remotamente. El exploit ha sido divulgado al público… | |
| Modificada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | Se ha identificado una debilidad en projectworlds Sistema Avanzado de Gestión de Bibliotecas 1.0. Afecta a una función desconocida del archivo /borrow.PHP. La ejecución de una manipulación del argumento roll_number puede conducir a una inyección SQL. Es posible lanzar el ataque remotamente. El exploit se ha puesto a… | |
| Modificada | Baja (2.1) | 0.39% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | Se ha descubierto una falla de seguridad en el Sistema de Gestión Avanzado de Bibliotecas 1.0 de projectworlds. Este problema afecta a un procesamiento desconocido del archivo /book_search.php. Realizar una manipulación del argumento book_pub/book_title resulta en inyección SQL. Es posible iniciar el ataque de forma… |