Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

233 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)1.00%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=reports/daily_services_report&date=.
ModificadaAlta (7.2)1.00%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_court_rental_report&date=.
ModificadaAlta (7.2)1.00%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_sales_report&date=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/services/view_service.php?id=.
ModificadaAlta (7.2)0.86%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/services/manage_service.php?id=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/manage_product.php?id=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/view_court.php?id=.
ModificadaCrítica (9.8)0.99%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/manage_court.php?id=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/view_product.php?id=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/manage_service_transaction&id=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/view_details&id=.
ModificadaAlta (7.2)1.0%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=sales/manage_sale&id=.
ModificadaCrítica (9.8)1.3%—Badminton Center Management System Project Badminton Center Management System2/6/20229/7/2026
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
ModificadaMedia (5.4)0.50%—Badminton Center Management System Project Badminton Center Management System24/5/202217/6/2026
Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_court_rental.
ModificadaCrítica (9.8)1.1%—Badminton Center Management System Project Badminton Center Management System24/5/202217/6/2026
Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.
ModificadaMedia (5.4)0.57%—Badminton Center Management System Project Badminton Center Management System23/5/202217/6/2026
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting.…
ModificadaAlta (7.5)1.3%—Crypto CronosCrypto EthermintCrypto Evmos21/12/202117/6/2026
Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. This problem has been patched in Cronos v0.6.5. There are no tested workarounds.…
ModificadaAlta (7.5)0.91%—Mintty Project Mintty6/6/202117/6/2026
Mintty before 3.4.7 mishandles Bracketed Paste Mode.
ModificadaAlta (7.5)1.6%—Mintty Project Mintty3/6/202117/6/2026
Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title…
ModificadaCrítica (9.8)1.2%—Minthcm26/4/202117/6/2026
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
ModificadaMedia (6.1)0.59%—Minthcm26/4/202117/6/2026
The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-upload.
ModificadaAlta (7.5)1.5%💥 PoCChainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be…
ModificadaAlta (7.5)1.3%—Chainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts.
ModificadaAlta (7.5)1.3%—Chainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch,…
Orbitaley — Vulnerabilidades