Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

3005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.99%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server8/8/202310/8/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.99%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server8/8/202310/8/2026
Microsoft Office Remote Code Execution Vulnerability
ModificadaCrítica (9.8)0.63%—Oduyo Online Collection8/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1.
ModificadaAlta (7.2)1.0%—Phpgurukul Online Nurse Hiring System8/8/20239/7/2026
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
ModificadaMedia (4.8)0.49%—Phpgurukul Online Nurse Hiring System8/8/20239/7/2026
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
ModificadaMedia (4.8)0.49%—Phpgurukul Online Nurse Hiring System8/8/20239/7/2026
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
ModificadaMedia (4.8)0.49%—Phpgurukul Online Nurse Hiring System8/8/20239/7/2026
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
ModificadaMedia (4.8)0.48%—Phpgurukul Online Nurse Hiring System8/8/20239/7/2026
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
ModificadaCrítica (9.8)0.74%—Mayurik Online Hospital Management System6/8/202317/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Hospital Management System v1.0. Se ha clasificado como crítica. Se ve afectada una función desconocida del archivo "patientlogin.php". La manipulación del argumento "loginid/password" conduce a una inyección SQL. Es posible lanzar el ataque de forma remota.…
ModificadaCrítica (9.8)1.4%—Phpgurukul Online Security Guards Hiring System4/8/202317/6/2026
Online Security Guards Hiring System v.1.0 de PHPGurukul es vulnerable a SQL Injection a través de osghs/admin/search.php.
ModificadaAlta (8.8)1.1%💥 PoCPhpgurukul Online Shopping Portal1/8/202317/6/2026
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
AnalizadaCrítica (9.8)0.82%—Oretnom23 Simple Online Men's Salon Management System28/7/202317/6/2026
A vulnerability was found in SourceCodester Simple Online Mens Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage_user&id=3. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaMedia (4.8)0.66%—Oretnom23 Simple Online Men's Salon Management System28/7/202317/6/2026
A vulnerability was found in SourceCodester Simple Online Mens Salon Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=user/list. The manipulation of the argument First Name/Last Name/Username leads to cross site scripting. The attack may be…
ModificadaCrítica (9.8)0.94%—Online Jewelry Store Project Online Jewelry Store28/7/202317/6/2026
A vulnerability has been found in SourceCodester Online Jewelry Store 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.56%—Phpgurukul Online Fire Reporting System27/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.
ModificadaMedia (6.1)0.58%—Phpgurukul Online Fire Reporting System27/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.
ModificadaMedia (5.4)0.37%—Basixonline Nex-forms17/7/202317/6/2026
The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.
ModificadaMedia (6.1)0.56%—Retro Cellphone Online Store Project Retro Cellphone Online Store15/7/202317/6/2026
A vulnerability classified as problematic was found in Campcodes Retro Cellphone Online Store 1.0. This vulnerability affects unknown code of the file /admin/modal_add_product.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)1.3%💥 PoCOretnom23 Online Computer AND Laptop Store13/7/202317/6/2026
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
ModificadaMedia (6.1)0.52%—Retro Cellphone Online Store Project Retro Cellphone Online Store13/7/202317/6/2026
A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.56%—Simple Online Piggery Management System Project Simple Online Piggery Management System12/7/202317/6/2026
Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent XSS.
ModificadaCrítica (9.8)23%💥 ExploitSimple Online Piggery Management System Project Simple Online Piggery Management System12/7/202317/6/2026
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
ModificadaCrítica (9.8)0.98%—Simple Online Piggery Management System Project Simple Online Piggery Management System12/7/202317/6/2026
Online Piggery Management System 1.0 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)0.89%—Code-projects Online Restaurant Management System12/7/202317/6/2026
Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc.
ModificadaMedia (5.5)0.76%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server11/7/202317/6/2026
Microsoft Excel Information Disclosure Vulnerability