Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.51% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.5) | 0.55% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. This issue affects some unknown processing of the file /adminpanel/admin/query/deleteCourseExe.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.51% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.51% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. This affects an unknown part of the file /adminpanel/admin/query/deleteQuestionExe.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.69% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /adminpanel/admin/query/loginExe.php. The manipulation of the argument pass leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.1) | 0.56% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminpanel/admin/facebox_modal/updateCourse.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched… | |
| Analizada | Media (6.1) | 0.58% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation of the argument id leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Media (6.5) | 0.57% | — | Campcodes Online Examination System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Campcodes Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /adminpanel/admin/facebox_modal/updateCourse.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (6.3) | 0.37% | — | Terminalfour FormbankTerminalfour | 21/2/2024 | 17/6/2026 | An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview. | |
| Modificada | Alta (8.8) | 0.35% | — | Ncratleos Terminal Handler | 8/2/2024 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security… | |
| Modificada | Media (6.5) | 0.34% | — | NCR Terminal Handler | 6/2/2024 | 17/6/2026 | Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection. | |
| Modificada | Alta (8.8) | 0.25% | — | Ncratleos Terminal Handler | 20/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types. | |
| Modificada | Crítica (9.8) | 0.74% | — | Ejinshan Terminal Security System | 20/1/2024 | 17/6/2026 | File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server. | |
| Modificada | Alta (8.8) | 0.67% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 0.65% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 0.67% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 0.67% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 0.51% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 0.67% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 0.67% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (4.8) | 0.45% | — | Incsub Forminator | 20/11/2023 | 17/6/2026 | The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup). | |
| Modificada | Media (4.9) | 0.86% | — | Incsub Forminator | 15/11/2023 | 17/6/2026 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary… | |
| Modificada | Media (5.3) | 0.53% | — | Kaoshifeng Yunfan Learning Examination System | 4/11/2023 | 17/6/2026 | An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function. | |
| Modificada | Crítica (9.8) | 0.70% | — | Online Examination System Project Online Examination System | 2/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (6.1) | 0.41% | — | Projectworlds Online Examination System | 1/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. |