Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.45%—Fabian Scholars Tracking System18/2/20268/9/2026
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password,…
ModificadaAlta (8.8)0.70%—Fabian Scholars Tracking System18/2/20268/9/2026
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without…
AnalizadaMedia (5.5)0.39%—Fabian Scholars Tracking System19/12/202517/6/2026
A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /home.php. Such manipulation of the argument post_content leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be…
ModificadaMedia (5.5)0.39%—Fabian Scholars Tracking System19/12/202517/6/2026
A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could…
AnalizadaMedia (5.5)0.39%—Fabian Scholars Tracking System19/12/202517/6/2026
A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /admin/delete_user.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be…
AplazadaMedia (6.5)0.28%—Nicholaswilson Graceful-email-obfuscationAI7/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation graceful-email-obfuscation allows Stored XSS.This issue affects Graceful Email Obfuscation: from n/a through <= 0.2.2.
AplazadaMedia (6.5)0.39%—Holanetworks Hola Free Video PlayerAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in holanetworks Hola Free Video Player hola-free-video-player allows DOM-Based XSS.This issue affects Hola Free Video Player: from n/a through <= 1.3.9.
ModificadaCrítica (9.8)0.31%—Code-projects Scholars Tracking System12/3/202417/6/2026
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
AnalizadaMedia (5.4)0.32%—Code-projects Scholars Tracking System12/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.
AnalizadaCrítica (9.8)0.57%—Code-projects Scholars Tracking System12/3/202417/6/2026
SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.
AnalizadaAlta (7.8)0.35%—Code-projects Scholars Tracking System12/3/202417/6/2026
SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.
AnalizadaAlta (7.8)0.42%—Fabian Scholars Tracking System5/3/202417/6/2026
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
AnalizadaMedia (5.4)0.37%—Code-projects Scholars Tracking System27/2/202417/6/2026
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
ModificadaAlta (8.8)0.84%—Hola VPN12/3/201817/6/2026
An issue was discovered in Hola 1.79.859. An unprivileged user could modify or overwrite the executable with arbitrary code, which would be executed the next time the service is started. Depending on the user that the service runs as, this could result in privilege escalation. The issue exists because of the…
ModificadaAlta (7.8)0.40%—Hola VPN9/11/201717/6/2026
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
ModificadaMedia (4.3)1.6%—Megnicholas Clean AND Simple Contact Form17/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.
ModificadaMedia (5.8)2.7%—Nicholasthompson Global Redirect25/6/201216/6/2026
Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.
ModificadaAlta (7.5)0.99%—Nicholas Berry Candid1/11/201116/6/2026
SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
ModificadaMedia (4.3)1.5%—Nicholas Berry Candid1/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.
ModificadaMedia (4.6)0.95%—Nicholas Marriott Tmux18/4/201116/6/2026
tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.
ModificadaMedia (5)1.5%—Nicholas Thompson Node Quick Find10/4/201116/6/2026
The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.
ModificadaMedia (5)1.5%—Nicholas Thompson Relevant Content23/3/201116/6/2026
The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.
ModificadaMedia (4.3)1.3%—Holacms12/4/200716/6/2026
Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.
ModificadaAlta (7.5)3.5%—Soholaunch PRO Edition8/11/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[docroot_path] parameter to (1) includes/shared_functions.php or (2)…
ModificadaMedia (5)3.0%—HolacmsAI2/5/200516/6/2026
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.