Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.78% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0 and classified as critical. This issue affects some unknown processing of the file admin\posts\manage_post.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Alta (8.8) | 0.78% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Discussion Forum Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin\categories\view_category.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.75% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Discussion Forum Site 1.0. This affects an unknown part of the file admin\categories\manage_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Alta (8.8) | 0.78% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Discussion Forum Site 1.0. Affected by this issue is some unknown functionality of the file classes\Users.php?f=registration. The manipulation of the argument username leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.4) | 0.64% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (5.4) | 0.61% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (6.5) | 0.39% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.5. This makes it possible for unauthenticated to logout a vctia connected account which… | |
| Modificada | Media (5.4) | 0.70% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal… | |
| Modificada | Media (6.5) | 0.42% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible… | |
| Modificada | Media (5.4) | 0.76% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | El plugin Event Registration Calendar By vcita, versiones hasta la 3.9.1 inlcusive, y el plugin Online Payments – Get Paid with PayPal, Square & Stripe, para WordPress son vulnerables a Cross-Site Scripting almacenado a través del parámetro "email" en versiones hasta la 1.3.1 inclusive, debido a un insuficiente… | |
| Modificada | Media (5.3) | 0.64% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check on the processAction function. This makes it… | |
| Modificada | Media (6.1) | 0.60% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 0.78% | — | Retro Cellphone Online Store Project Retro Cellphone Online Store | 2/6/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/modal_add_product.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Exam Form Submission Project Online Exam Form Submission | 2/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/update_s6.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.40% | — | Collaboraoffice Collabora Online | 31/5/2023 | 17/6/2026 | Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an administrator opened the admin console and… | |
| Modificada | Media (6.1) | 0.63% | — | Students Online Internship Timesheet System Project Students Online Internship Timesheet System | 30/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesheet Syste 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_company. The manipulation of the argument name with the input… | |
| Modificada | Crítica (9.8) | 0.78% | — | Students Online Internship Timesheet System Project Students Online Internship Timesheet System | 29/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. Affected is an unknown function of the file rendered_report.php of the component GET Parameter Handler. The manipulation of the argument sid leads to sql injection. It is possible to launch… | |
| Modificada | Media (6.1) | 0.55% | — | Online Jewelry Store Project Online Jewelry Store | 24/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file customer.php of the component POST Parameter Handler. The manipulation of the argument Custid leads to cross site scripting. The attack may be launched… | |
| Modificada | Alta (8.8) | 0.27% | — | Pingonline Dyslexiefont Free | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PingOnline Dyslexiefont Free plugin <= 1.0.0 versions. | |
| Modificada | Crítica (9.8) | 0.73% | — | Online Jewelry Store Project Online Jewelry Store | 19/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Jewelry Store 1.0. Affected by this vulnerability is an unknown functionality of the file supplier.php of the component POST Parameter Handler. The manipulation of the argument suppid leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Alta (8.8) | 0.73% | — | Online Exam System Project Online Exam System | 17/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Exam System 1.0. This issue affects some unknown processing of the file /jurusanmatkul/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.73% | — | Online Exam System Project Online Exam System | 17/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Exam System 1.0. This vulnerability affects unknown code of the file /kelasdosen/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 1.5% | — | Oretnom23 Online Computer AND Laptop Store | 16/5/2023 | 17/6/2026 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save. | |
| Modificada | Media (6.1) | 0.40% | — | Collabora Online | 15/5/2023 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice technology. This vulnerability report describes a reflected XSS vulnerability with full CSP bypass in Nextcloud installations using the recommended bundle. The vulnerability can be exploited to perform a trivial account takeover attack. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /jurusan/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to launch the attack remotely. The… |