Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
3004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 15/7/2026 | A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.50% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 14/7/2026 | A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 14/7/2026 | A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 14/7/2026 | A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.25% | — | Basixonline Nex-formsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2. | |
| Aplazada | Baja (2.1) | 0.42% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Coderastro Simple Online Leave Management SystemAI | 13/7/2026 | 14/7/2026 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Media (6.9) | 0.65% | — | Rafymrx Toko-online-rotiAI | 12/7/2026 | 14/7/2026 | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery.… | |
| Aplazada | Media (5.5) | 0.41% | — | Rafymrx Toko-online-rotiAI | 12/7/2026 | 13/7/2026 | A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknown functionality of the file proses/add.php. The manipulation of the argument kode_produk/kd_cs results in sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.41% | — | Rafymrx Toko-online-rotiAI | 12/7/2026 | 15/7/2026 | A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unknown functionality of the file proses/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Alta (7.2) | 8.8% | 💥 Exploit | Planyo Online Reservation SystemAI | 11/7/2026 | 13/7/2026 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The… | |
| Aplazada | Crítica (9.1) | 1.0% | — | Xerte Online ToolsAI | 9/7/2026 | 9/7/2026 | A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Xerte Online ToolsAI | 9/7/2026 | 9/7/2026 | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Food Order SystemAI | 9/7/2026 | 9/7/2026 | A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Simple Online Leave Management SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might… |