Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /matkul/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /kelas/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been classified as critical. This affects an unknown part of the file /dosen/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mahasiswa/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This vulnerability affects unknown code of the file view_categories.php. The manipulation of the argument c leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file view_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.88% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file products.php. The manipulation of the argument c leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.70% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. The manipulation of the argument search leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.73% | — | Online Exam System Project Online Exam System | 11/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. This affects an unknown part of the file adminpanel/admin/facebox_modal/updateCourse.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 0.80% | — | Online Internship Management System Project Online Internship Management System | 11/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Internship Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/login.php of the component POST Parameter Handler. The manipulation of the argument email leads to sql injection. The attack may be… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 10/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects the function exec of the file disapprove_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.34% | — | Touki-kyoutaku-online Shinseiyo Sogo Soft | 10/5/2023 | 17/6/2026 | Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker. | |
| Modificada | Alta (7.8) | 0.70% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/5/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 0.83% | — | Janobe Online Reviewer System | 9/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql… | |
| Modificada | Crítica (9.8) | 0.98% | 💥 PoC | Online Pizza Ordering System Project Online Pizza Ordering System | 8/5/2023 | 17/6/2026 | SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. | |
| Modificada | Alta (7.2) | 45% | 💥 PoC | Basixonline Nex-forms | 8/5/2023 | 17/6/2026 | The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query. | |
| Modificada | Alta (8.8) | 0.87% | — | Avirato Hotels Online Booking Engine | 8/5/2023 | 17/6/2026 | The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks. | |
| Modificada | Crítica (9.8) | 0.98% | — | Oretnom23 Online Food Ordering System | 5/5/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Alta (7.5) | 2.8% | — | Gavazzionline Powersoft | 4/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device. | |
| Modificada | Crítica (9.8) | 0.72% | — | Online DJ Management System Project Online DJ Management System | 1/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online DJ Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/bookings/view_details.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated… | |
| Modificada | Media (4.8) | 0.61% | — | Online DJ Management System Project Online DJ Management System | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online DJ Management System 1.0. Affected by this issue is some unknown functionality of the file classes/Master.php?f=save_event. The manipulation of the argument name leads to cross site scripting. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.83% | — | Online DJ Management System Project Online DJ Management System | 28/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online DJ Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/inquiries/view_details.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can… | |
| Modificada | Crítica (9.8) | 0.88% | — | Online DJ Management System Project Online DJ Management System | 28/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online DJ Management System 1.0. Affected is an unknown function of the file admin/events/manage_event.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack… | |
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Online Pizza Ordering System Project Online Pizza Ordering System | 23/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/ajax.php?action=save_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has… |