Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.16% | — | Zookatron Mybooktable BookstoreAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0. | |
| Aplazada | Media (5.5) | 0.38% | — | Ywxbear Php-bookstore-website-exampleAIYwxbear PHP Basic Bookstore WebsiteAI | 11/10/2025 | 17/6/2026 | A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the argument register_username results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /cart.php. The manipulation of the argument remove results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Bookstore Management System | 23/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument unm causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (4.8) | 0.51% | — | 1000projects Bookstore Management System | 11/2/2025 | 17/6/2026 | A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file process_book_add.php of the component Add Book Page. The manipulation of the argument Book Name leads to cross site scripting. The attack can be initiated… | |
| Analizada | Media (5.1) | 0.67% | — | 1000projects Bookstore Management System | 11/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file process_users_del.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. | |
| Analizada | Media (5.3) | 0.55% | — | 1000projects Bookstore Management System | 11/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file addtocart.php. The manipulation of the argument bcid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.1) | 0.49% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted… | |
| Analizada | Media (5.3) | 0.41% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller/admin/AdminUserControlle.java. The manipulation leads to cross site scripting. The attack may be initiated remotely.… | |
| Analizada | Media (5.3) | 0.31% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore/web/controller/BookInfoController.java. The manipulation of the argument keywords leads to cross site scripting. The… | |
| Analizada | Media (5.3) | 0.43% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack… | |
| Analizada | Media (6.9) | 0.68% | — | 1000projects Bookstore Management System | 29/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /order_process.php. The manipulation of the argument fnm leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.1) | 0.60% | — | 1000projects Bookstore Management System | 17/12/2024 | 17/6/2026 | A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection. | |
| Analizada | Media (6.9) | 0.36% | — | 1000projects Bookstore Management System | 25/11/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.85% | — | 1000projects Bookstore Management System | 21/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file /forget_password_process.php. The manipulation of the argument unm leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.70% | — | 1000projects Bookstore Management System | 8/11/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/process_category_add.php. The manipulation of the argument cat leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | 1000projects Bookstore Management System | 8/11/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /book_list.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.70% | — | 1000projects Bookstore Management System | 8/11/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/process_category_edit.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.65% | — | 1000projects Bookstore Management System | 7/11/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/login_process.php of the component Login. The manipulation of the argument unm/pwd leads to sql injection. The attack may be launched… | |
| Analizada | Media (6.9) | 0.70% | — | 1000projects Bookstore Management System | 7/11/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /contact_process.php. The manipulation of the argument fnm leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.93% | — | 1000projects Bookstore Management System | 5/11/2024 | 17/6/2026 | A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.93% | — | 1000projects Bookstore Management System | 5/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file search.php. The manipulation of the argument s leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (6.1) | 0.16% | — | Stormhillmedia Mybook Table Bookstore | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable.This issue affects MyBookTable Bookstore: from n/a through <= 3.3.9. |