Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.99% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 8/8/2023 | 10/8/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.99% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 8/8/2023 | 10/8/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 0.63% | — | Oduyo Online Collection | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1. | |
| Modificada | Alta (7.2) | 1.0% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal. | |
| Modificada | Media (4.8) | 0.49% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal. | |
| Modificada | Media (4.8) | 0.49% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal. | |
| Modificada | Media (4.8) | 0.49% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal. | |
| Modificada | Media (4.8) | 0.48% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin. | |
| Modificada | Crítica (9.8) | 0.74% | — | Mayurik Online Hospital Management System | 6/8/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Hospital Management System v1.0. Se ha clasificado como crítica. Se ve afectada una función desconocida del archivo "patientlogin.php". La manipulación del argumento "loginid/password" conduce a una inyección SQL. Es posible lanzar el ataque de forma remota.… | |
| Modificada | Crítica (9.8) | 1.4% | — | Phpgurukul Online Security Guards Hiring System | 4/8/2023 | 17/6/2026 | Online Security Guards Hiring System v.1.0 de PHPGurukul es vulnerable a SQL Injection a través de osghs/admin/search.php. | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Phpgurukul Online Shopping Portal | 1/8/2023 | 17/6/2026 | Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php. | |
| Analizada | Crítica (9.8) | 0.82% | — | Oretnom23 Simple Online Men's Salon Management System | 28/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Online Mens Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage_user&id=3. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (4.8) | 0.66% | — | Oretnom23 Simple Online Men's Salon Management System | 28/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Online Mens Salon Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=user/list. The manipulation of the argument First Name/Last Name/Username leads to cross site scripting. The attack may be… | |
| Modificada | Crítica (9.8) | 0.94% | — | Online Jewelry Store Project Online Jewelry Store | 28/7/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Jewelry Store 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.56% | — | Phpgurukul Online Fire Reporting System | 27/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field. | |
| Modificada | Media (6.1) | 0.58% | — | Phpgurukul Online Fire Reporting System | 27/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields. | |
| Modificada | Media (5.4) | 0.37% | — | Basixonline Nex-forms | 17/7/2023 | 17/6/2026 | The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature. | |
| Modificada | Media (6.1) | 0.56% | — | Retro Cellphone Online Store Project Retro Cellphone Online Store | 15/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Retro Cellphone Online Store 1.0. This vulnerability affects unknown code of the file /admin/modal_add_product.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.3% | 💥 PoC | Oretnom23 Online Computer AND Laptop Store | 13/7/2023 | 17/6/2026 | Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role. | |
| Modificada | Media (6.1) | 0.52% | — | Retro Cellphone Online Store Project Retro Cellphone Online Store | 13/7/2023 | 17/6/2026 | A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.56% | — | Simple Online Piggery Management System Project Simple Online Piggery Management System | 12/7/2023 | 17/6/2026 | Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent XSS. | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Simple Online Piggery Management System Project Simple Online Piggery Management System | 12/7/2023 | 17/6/2026 | Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php." | |
| Modificada | Crítica (9.8) | 0.98% | — | Simple Online Piggery Management System Project Simple Online Piggery Management System | 12/7/2023 | 17/6/2026 | Online Piggery Management System 1.0 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.89% | — | Code-projects Online Restaurant Management System | 12/7/2023 | 17/6/2026 | Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc. | |
| Modificada | Media (5.5) | 0.76% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 11/7/2023 | 17/6/2026 | Microsoft Excel Information Disclosure Vulnerability |