Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.73% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Media (4.8) | 0.46% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Media (6.1) | 0.56% | — | Online PET Shop WE APP Project Online PET Shop WE APP | 26/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pet Shop We App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /pet_shop/admin/orders/update_status.php. The manipulation of the argument oid with the input 1"><script>alert(1111)</script> leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 0.58% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 26/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file tracking/admin/add_acc.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The… | |
| Modificada | Crítica (9.8) | 0.81% | — | Online Reviewer Management System Project Online Reviewer Management System | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Reviewer Management System 1.0. Affected is an unknown function of the file /reviewer_0/admins/assessments/pretest/questions-view.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.… | |
| Modificada | Alta (7.5) | 1.2% | — | Online Book Store Project Online Book Store | 24/2/2023 | 17/6/2026 | Una vulnerabilidad de inyección SQL en sourcecodester online-book-store 1.0 permite a atacantes remotos ver información confidencial a través del parámetro id en la URL de la aplicación. | |
| Modificada | Media (5.1) | 0.65% | — | Online Boat Reservation System Project Online Boat Reservation System | 24/2/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Boat Reservation System 1.0 y se ha clasificado como problemática. Una función desconocida del archivo /boat/login.php del componente POST Parameter Handler es afectada por esta vulnerabilidad. La manipulación del argumento un conduce a cross-site scripting.… | |
| Modificada | Alta (8.8) | 0.46% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 23/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0. This issue affects some unknown processing of the file admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.58% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 23/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file index.php?page=checkout. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 0.66% | — | Online Services Project Online Services | 23/2/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17. | |
| Modificada | Crítica (9.8) | 0.65% | — | Online Student Admission System Project Online Student Admission System | 22/2/2023 | 17/6/2026 | Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |
| Modificada | Alta (8.8) | 0.78% | — | Oretnom23 Online Eyewear Shop | 22/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=orders/view_order. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.47% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 18/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_prod.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.66% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 18/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vulnerability is the function delete_category of the file ajax.php of the component POST Parameter Handler. The manipulation leads to missing authentication. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 1.2% | — | Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql | 17/2/2023 | 17/6/2026 | Existe una vulnerabilidad de inyección SQL en Projectworlds Online Doctor Appointment Booking System, que permite a los atacantes obtener información confidencial a través del parámetro q en el endpoint getuser.php. | |
| Modificada | Crítica (9.8) | 0.61% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 17/2/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Pizza Ordering System 1.0 y clasificada como crítica. Esta vulnerabilidad afecta a un código desconocido del archivo /php-opos/index.php. La manipulación del argumento ID conduce a la inyección SQL. El ataque se puede iniciar de forma remota. El exploit ha… | |
| Modificada | Crítica (9.8) | 85% | 💥 PoC | Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+4 | 14/2/2023 | 19/8/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 0.74% | — | Oretnom23 Online Food Ordering System | 13/2/2023 | 17/6/2026 | Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Oretnom23 Online Food Ordering System | 13/2/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Baja (3.7) | 0.85% | — | Mayurik Best Online News Portal | 12/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be… | |
| Modificada | Crítica (9.8) | 0.81% | — | Mayurik Best Online News Portal | 12/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.1) | 0.39% | — | Oretnom23 Online Eyewear Shop | 7/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact… | |
| Modificada | Media (6.1) | 0.51% | — | Openseamap Online Chart | 7/2/2023 | 17/6/2026 | Se encontró una vulnerabilidad en OpenSeaMap online_chart 1.2. Ha sido clasificada como problemática. La función init del archivo index.php es afectada por la vulnerabilidad. La manipulación del argumento mtext conduce a cross-site scripting. Es posible lanzar el ataque de forma remota. La actualización a la versión… | |
| Modificada | Crítica (9.8) | 0.55% | — | Oretnom23 Online Eyewear Shop | 6/2/2023 | 17/6/2026 | Se encontró una vulnerabilidad en SourceCodester Online Eyewear Shop 1.0. Ha sido clasificada como crítica. Esto afecta a la función update_cart del archivo /oews/classes/Master.php?f=update_cart del componente HTTP POST Request Handler. La manipulación del argumento cart_id conduce a la inyección de SQL. Es posible… | |
| Modificada | Media (6.1) | 0.46% | — | Oretnom23 Online Food Ordering System | 6/2/2023 | 17/6/2026 | Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php. |