Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

3005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)0.68%—Phpgurukul Online Shopping Portal10/7/202317/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely.…
ModificadaMedia (4.8)0.54%—Phpgurukul Online Fire Reporting System10/7/202317/6/2026
Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.
ModificadaMedia (6.1)0.60%—Phpgurukul Online Security Guards Hiring System10/7/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.
ModificadaCrítica (9.8)2.0%—Online ART Gallery Project Online ART Gallery10/7/202317/6/2026
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
ModificadaMedia (6.1)0.63%—Online Pizza Ordering System Project Online Pizza Ordering System10/7/202317/6/2026
Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?page=categories" Category item.
ModificadaMedia (6.5)0.38%—Online Examination System Project Online Examination System7/7/202317/6/2026
The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a…
ModificadaCrítica (9.8)0.82%—Retro Cellphone Online Store Project Retro Cellphone Online Store30/6/202317/6/2026
A vulnerability, which was classified as critical, was found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/edit_product.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)0.86%—Online Hotel Management System Project Online Hotel Management System29/6/202317/6/2026
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection.
ModificadaMedia (6.1)0.66%—Online Hotel Management System Project Online Hotel Management System29/6/202317/6/2026
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box.
ModificadaMedia (6.5)0.59%—Retro Cellphone Online Store Project Retro Cellphone Online Store25/6/202317/6/2026
A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be launched remotely. The exploit…
ModificadaMedia (6.1)0.56%—Online School Fees System Project Online School Fees System23/6/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online School Fees System 1.0. Affected by this vulnerability is an unknown functionality of the file /paysystem/datatable.php of the component GET Parameter Handler. The manipulation of the argument doj leads to cross site scripting. The attack can…
ModificadaCrítica (9.8)0.84%—Online School Fees System Project Online School Fees System20/6/202317/6/2026
A vulnerability was found in SourceCodester Online School Fees System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajx.php of the component GET Parameter Handler. The manipulation of the argument name_startsWith leads to sql injection. The attack may be launched…
ModificadaCrítica (9.8)0.69%—Online Shopping System Advanced Project Online Shopping System Advanced20/6/202317/6/2026
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched…
ModificadaMedia (5.4)0.51%—Bearsthemes Sermons Online19/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
ModificadaMedia (5.4)0.44%—Slideonline Project Sideonline19/6/202317/6/2026
The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.59%—Online-shopping-system-advanced Project Online-shopping-system-advanced18/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaMedia (6.1)0.56%—Online School Fees System Project Online School Fees System14/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Online School Fees System 1.0. This affects an unknown part of the file /paysystem/branch.php of the component POST Parameter Handler. The manipulation of the argument branch leads to cross site scripting. It is possible to initiate the…
ModificadaAlta (7.8)2.7%💥 ExploitMicrosoft OfficeMicrosoft Office Online Server14/6/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.8)44%—Microsoft 365 AppsMicrosoft ExcelMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server14/6/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.8)54%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/6/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaMedia (4.3)0.48%—Vcita Online Booking & Scheduling Calendar9/6/202317/6/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal…
AnalizadaAlta (8.8)0.84%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Discussion Forum Site 1.0. This affects an unknown part of the file admin\posts\view_post.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (8.8)0.78%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user\manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaAlta (8.8)0.75%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file posts\manage_post.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaAlta (8.8)0.84%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file admin\user\manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
Orbitaley — Vulnerabilidades