Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.42% | — | Qgis Qwc2AIQgis Qwc2 Registration GUIAI | 13/10/2025 | 17/6/2026 | Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant arbitrary JavaScript code in the page | |
| Aplazada | Media (4.7) | 0.21% | — | CM RegistrationAI | 11/10/2025 | 17/6/2026 | The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.5.6. This is due to insufficient validation on the redirect url supplied via the 'redirect_url' parameter. This makes it possible for… | |
| Analizada | Alta (8.3) | 0.41% | 💥 PoC | Webkul Bagisto | 10/10/2025 | 17/6/2026 | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser,… | |
| Analizada | Media (6.5) | 0.41% | — | Webkul Bagisto | 9/10/2025 | 17/6/2026 | An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly. | |
| Aplazada | Alta (7.2) | 0.41% | — | Metagauss RegistrationmagicAI | 8/10/2025 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Analizada | Baja (2) | 0.41% | — | Fabian Online Course Registration Site | 6/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument coursecode can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online Course Registration Site | 6/10/2025 | 17/6/2026 | A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.5) | 0.32% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application. | |
| Analizada | Media (6.1) | 0.29% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information. | |
| Analizada | Media (6.5) | 0.36% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. | |
| Analizada | Crítica (9.8) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | |
| Analizada | Alta (7.5) | 0.43% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering. | |
| Analizada | Alta (7.5) | 0.39% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally. | |
| Analizada | Media (5.3) | 0.40% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration. | |
| Aplazada | Media (5.3) | 0.15% | — | Restrict User RegistrationAI | 3/10/2025 | 30/9/2026 | The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the update() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Analizada | Media (4.8) | 0.26% | — | Phpgurukul User Registration & Login AND User Management System | 30/9/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters. | |
| Analizada | Media (5.5) | 0.43% | — | Phpgurukul Online Course Registration | 18/9/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /my-profile.php. Performing manipulation of the argument cgpa results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (4.9) | 0.34% | — | User Registration MembershipAI | 6/9/2025 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Online Course Registration | 5/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (6.5) | 0.17% | — | Sudar Muthu WP Github GistAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sudar Muthu WP Github Gist wp-github-gist allows Stored XSS.This issue affects WP Github Gist: from n/a through <= 0.5. | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Online Course Registration | 31/8/2025 | 17/6/2026 | A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and… | |
| Aplazada | Baja (2.1) | 0.25% | — | Getgist ChatboxAI | 29/8/2025 | 17/6/2026 | A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown function of the file /chat.php. The manipulation of the argument user_id results in sql injection. The attack may be performed from a remote location. The exploit has been made public and could be… |