Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3206▲ 632 respecto a la semana anterior
Críticas / altas1515▲ 119 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.8% | 💥 PoC | Microsoft Office Online ServerMicrosoft Office WEB Apps Server | 14/3/2023 | 17/6/2026 | Microsoft Excel Denial of Service Vulnerability | |
| Modificada | Media (6.5) | 0.26% | — | Oretnom23 Online Food Ordering System | 14/3/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request. | |
| Modificada | Media (6.1) | 0.56% | — | Online Student Management System Project Online Student Management System | 14/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Online Student Management System 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.56% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 14/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin/traveller_details.php. The manipulation of the argument address leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 14/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.89% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 14/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is the function save_menu. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.70% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 14/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.75% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 13/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.60% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 13/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be… | |
| Modificada | Media (4.8) | 0.60% | — | Gadget Works Online Ordering System Project Gadget Works Online Ordering System | 12/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Gadget Works Online Ordering System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /philosophy/admin/user/controller.php?action=add of the component Add New User. The manipulation of the argument U_NAME leads to cross site… | |
| Modificada | Crítica (9.8) | 0.73% | — | Gadget Works Online Ordering System Project Gadget Works Online Ordering System | 12/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Gadget Works Online Ordering System 1.0. This affects an unknown part of the file /philosophy/admin/login.php of the component POST Parameter Handler. The manipulation of the argument user_email leads to sql injection. It is possible to… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 10/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file admin/prof.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 10/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Graduate Tracer System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/search_it.php. The manipulation of the argument input leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 10/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file admin/adminlog.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.79% | — | Online Student Management System Project Online Student Management System | 9/3/2023 | 17/6/2026 | Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php. | |
| Modificada | Crítica (9.8) | 0.79% | — | Online Student Management System Project Online Student Management System | 9/3/2023 | 17/6/2026 | Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php. | |
| Modificada | Media (6.1) | 0.48% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 9/3/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | |
| Modificada | Media (6.1) | 0.43% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 9/3/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter. | |
| Modificada | Crítica (9.8) | 0.87% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 9/3/2023 | 17/6/2026 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php. | |
| Modificada | Media (6.1) | 0.48% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 9/3/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | |
| Modificada | Crítica (9.8) | 0.87% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 9/3/2023 | 17/6/2026 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php. | |
| Modificada | Alta (8.1) | 0.57% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 9/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects the function mysqli_query of the file admin_cs.php. The manipulation leads to sql injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is… | |
| Modificada | Media (6.3) | 0.55% | — | Basixonline Nex-forms | 7/3/2023 | 17/6/2026 | The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber level permissions and above to invoke these functions… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Catering Reservation System Project Online Catering Reservation System | 28/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 0.65% | — | Online Student Management System Project Online Student Management System | 28/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The… |