Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

3005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.73%—Online Reviewer Management System Project Online Reviewer Management System28/2/202317/6/2026
An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php.
ModificadaMedia (4.8)0.46%—Online Reviewer Management System Project Online Reviewer Management System28/2/202317/6/2026
An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php.
ModificadaMedia (6.1)0.56%—Online PET Shop WE APP Project Online PET Shop WE APP26/2/202317/6/2026
A vulnerability has been found in SourceCodester Online Pet Shop We App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /pet_shop/admin/orders/update_status.php. The manipulation of the argument oid with the input 1"><script>alert(1111)</script> leads to cross site scripting. The…
ModificadaCrítica (9.8)0.58%—Online Graduate Tracer System Project Online Graduate Tracer System26/2/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file tracking/admin/add_acc.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The…
ModificadaCrítica (9.8)0.81%—Online Reviewer Management System Project Online Reviewer Management System26/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Reviewer Management System 1.0. Affected is an unknown function of the file /reviewer_0/admins/assessments/pretest/questions-view.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.…
ModificadaAlta (7.5)1.2%—Online Book Store Project Online Book Store24/2/202317/6/2026
Una vulnerabilidad de inyección SQL en sourcecodester online-book-store 1.0 permite a atacantes remotos ver información confidencial a través del parámetro id en la URL de la aplicación.
ModificadaMedia (5.1)0.65%—Online Boat Reservation System Project Online Boat Reservation System24/2/202317/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Boat Reservation System 1.0 y se ha clasificado como problemática. Una función desconocida del archivo /boat/login.php del componente POST Parameter Handler es afectada por esta vulnerabilidad. La manipulación del argumento un conduce a cross-site scripting.…
ModificadaAlta (8.8)0.46%—Online Pizza Ordering System Project Online Pizza Ordering System23/2/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0. This issue affects some unknown processing of the file admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has…
ModificadaMedia (5.4)0.58%—Online Pizza Ordering System Project Online Pizza Ordering System23/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file index.php?page=checkout. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)0.66%—Online Services Project Online Services23/2/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.
ModificadaCrítica (9.8)0.65%—Online Student Admission System Project Online Student Admission System22/2/202317/6/2026
Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
ModificadaAlta (8.8)0.78%—Oretnom23 Online Eyewear Shop22/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=orders/view_order. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has…
ModificadaCrítica (9.8)0.47%—Online Pizza Ordering System Project Online Pizza Ordering System18/2/202317/6/2026
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_prod.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The…
ModificadaCrítica (9.8)0.66%—Online Pizza Ordering System Project Online Pizza Ordering System18/2/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vulnerability is the function delete_category of the file ajax.php of the component POST Parameter Handler. The manipulation leads to missing authentication. The attack can be launched remotely. The…
ModificadaCrítica (9.8)1.2%—Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql17/2/202317/6/2026
Existe una vulnerabilidad de inyección SQL en Projectworlds Online Doctor Appointment Booking System, que permite a los atacantes obtener información confidencial a través del parámetro q en el endpoint getuser.php.
ModificadaCrítica (9.8)0.61%—Online Pizza Ordering System Project Online Pizza Ordering System17/2/202317/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Pizza Ordering System 1.0 y clasificada como crítica. Esta vulnerabilidad afecta a un código desconocido del archivo /php-opos/index.php. La manipulación del argumento ID conduce a la inyección SQL. El ataque se puede iniciar de forma remota. El exploit ha…
ModificadaCrítica (9.8)85%💥 PoCMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+414/2/202319/8/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (7.5)0.74%—Oretnom23 Online Food Ordering System13/2/202317/6/2026
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
ModificadaCrítica (9.8)1.1%—Oretnom23 Online Food Ordering System13/2/202317/6/2026
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaBaja (3.7)0.85%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be…
ModificadaCrítica (9.8)0.81%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaMedia (6.1)0.39%—Oretnom23 Online Eyewear Shop7/2/202317/6/2026
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact…
ModificadaMedia (6.1)0.51%—Openseamap Online Chart7/2/202317/6/2026
Se encontró una vulnerabilidad en OpenSeaMap online_chart 1.2. Ha sido clasificada como problemática. La función init del archivo index.php es afectada por la vulnerabilidad. La manipulación del argumento mtext conduce a cross-site scripting. Es posible lanzar el ataque de forma remota. La actualización a la versión…
ModificadaCrítica (9.8)0.55%—Oretnom23 Online Eyewear Shop6/2/202317/6/2026
Se encontró una vulnerabilidad en SourceCodester Online Eyewear Shop 1.0. Ha sido clasificada como crítica. Esto afecta a la función update_cart del archivo /oews/classes/Master.php?f=update_cart del componente HTTP POST Request Handler. La manipulación del argumento cart_id conduce a la inyección de SQL. Es posible…
ModificadaMedia (6.1)0.46%—Oretnom23 Online Food Ordering System6/2/202317/6/2026
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.