Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.73% | — | Oretnom23 Online Eyewear Shop | 22/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. This affects an unknown part of the file /admin/orders/update_status.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Online Computer AND Laptop Store | 22/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation of the argument c/s leads to sql injection. The attack can be launched remotely. The… | |
| Modificada | Alta (7.5) | 0.61% | — | Campcodes Retro Basketball Shoes Online Store | 21/4/2023 | 31/7/2026 | A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.5) | 0.61% | — | Campcodes Retro Basketball Shoes Online Store | 21/4/2023 | 31/7/2026 | A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file contactus1.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.74% | — | Campcodes Retro Basketball Shoes Online Store | 21/4/2023 | 31/7/2026 | A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 0.61% | — | Campcodes Retro Basketball Shoes Online Store | 21/4/2023 | 31/7/2026 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.61% | — | Campcodes Retro Basketball Shoes Online Store | 21/4/2023 | 31/7/2026 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file faqs.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.36% | — | Online Jewelry Shop Project Online Jewelry Shop | 19/4/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL. | |
| Modificada | Media (5.4) | 0.48% | — | Online Jewelry Shop Project Online Jewelry Shop | 19/4/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter. | |
| Modificada | Alta (7.5) | 0.71% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 18/4/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 18/4/2023 | 17/6/2026 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface. | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 18/4/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface. | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Thesis Archiving System 1.0. This affects an unknown part of the file /admin/curriculum/view_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/students/view_details.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.98% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0. It has been classified as critical. Affected is an unknown function of the file projects_per_curriculum.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.98% | — | Online Thesis Archiving System Project Online Thesis Archiving System | 18/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Thesis Archiving System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/departments/view_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.57% | — | Campcodes Online Traffic Offense Management System | 14/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Campcodes Online Traffic Offense Management System 1.0. This issue affects some unknown processing of the file /admin/offenses/view_details.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated… | |
| Analizada | Media (6.1) | 0.64% | — | Campcodes Online Traffic Offense Management System | 14/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Online Traffic Offense Management System 1.0. This vulnerability affects unknown code of the file /classes/Users.phpp. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Alta (8.8) | 0.74% | — | Campcodes Online Traffic Offense Management System | 14/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Traffic Offense Management System 1.0. This affects an unknown part of the file /admin/offenses/view_details.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.79% | — | Campcodes Online Traffic Offense Management System | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Traffic Offense Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.95% | — | Campcodes Online Traffic Offense Management System | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Online Traffic Offense Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Login.php. The manipulation of the argument password leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.1) | 0.60% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability has been found in Campcodes Advanced Online Voting System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/config_save.php. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.75% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affects an unknown part of the file /admin/positions_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… |