Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.43% | — | Birtech Information Technologies Industry AND Trade SensawayAI | 9/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server. This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable… | |
| Aplazada | Media (6.5) | 0.28% | — | Birtech Information Technologies Industry AND Trade SensewayAI | 9/2/2026 | 17/6/2026 | Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix… | |
| Aplazada | Alta (7.3) | 0.33% | — | Birtech Information Technologies Industry AND Trade SensewayAI | 9/2/2026 | 17/6/2026 | Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities.… | |
| Aplazada | Media (5.3) | 1.6% | 💥 Exploit | Birth Chart CompatibilityAI | 22/7/2025 | 17/6/2026 | The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to insufficient protection against directly accessing the plugin's index.php file, which causes an error exposing the full path. This makes it possible for unauthenticated… | |
| Analizada | Media (5.3) | 0.27% | — | Phpgurukul Online Birth Certificate System | 31/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/registered-users.php. The manipulation of the argument del leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.27% | — | Phpgurukul Online Birth Certificate System | 31/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file /admin/all-applications.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.26% | — | Phpgurukul Online Birth Certificate System | 31/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/users-applications.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.40% | — | Phpgurukul Online Birth Certificate System | 3/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/between-dates-report.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.36% | — | Phpgurukul Online Birth Certificate System | 2/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.36% | — | Phpgurukul Online Birth Certificate System | 1/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.4) | 0.28% | 💥 PoC | Phpgurukul Online Birth Certificate System | 3/2/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php. | |
| Analizada | Media (6.1) | 0.20% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php. | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access… | |
| Analizada | Media (5.4) | 0.14% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts. | |
| Analizada | Media (5.4) | 0.19% | — | Phpgurukul Online Birth Certificate System | 17/12/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field. | |
| Analizada | Media (6.9) | 0.53% | — | Oretnom23 Online Birth Certificate Management System | 17/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.3) | 0.43% | — | Oretnom23 Online Birth Certificate Management System | 14/10/2022 | 17/6/2026 | Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability | |
| Modificada | Media (6.1) | 0.39% | — | Oretnom23 Online Birth Certificate Management System | 14/10/2022 | 17/6/2026 | Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability. | |
| Modificada | Alta (8.8) | 0.36% | — | Oretnom23 Online Birth Certificate Management System | 14/10/2022 | 17/6/2026 | Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (5.4) | 0.35% | — | Oretnom23 Online Birth Certificate Management System | 14/10/2022 | 17/6/2026 | Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability. | |
| Modificada | Media (4.8) | 0.59% | — | Birthdays Widget Project Birthdays Widget | 30/5/2022 | 17/6/2026 | The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Phpgurukul Online Birth Certificate System | 23/5/2022 | 9/7/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Eclipse Birt | 31/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Ridder Roeland Birthsys | 19/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable. NOTE: a vector regarding the $date parameter and data.php (date.php) was originally reported, but this appears to be in error. |