Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.30% | — | Codeastro Internet Banking System | 17/4/2025 | 17/6/2026 | Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php. | |
| Analizada | Alta (8.8) | 0.88% | — | Codeastro Internet Banking System | 10/4/2025 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php. | |
| Analizada | Media (4.8) | 0.27% | — | Codeastro Internet Banking System | 9/4/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0. | |
| Analizada | Alta (7.3) | 0.45% | — | Codeastro Internet Banking System | 22/1/2025 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The manipulation of the argument Client Full Name with the input <meta http-equiv="refresh" content="0; url=https://vuldb.com" /> leads to open… | |
| Modificada | Media (5.4) | 0.56% | — | Martinmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. The manipulation of the argument Client Full Name leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.74% | — | Codeastro Internet Banking System | 2/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 23/10/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 23/10/2023 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905--><ScRiPt%20>alert(9523)</ScRiPt><!-- leads to cross site scripting. The… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 23/10/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_withdraw_money.php. The manipulation of the argument account_number with the input 287359614--><ScRiPt%20>alert(1234)</ScRiPt><!-- leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.47% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file pages_transfer_money.php. The manipulation of the argument account_number with the input 357146928--><ScRiPt%20>alert(9206)</ScRiPt><!-- leads to cross… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt> leads to… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross site scripting. It is possible to launch… | |
| Modificada | Crítica (9.8) | 0.65% | — | Martmbithi Internet Banking System | 22/10/2023 | 17/6/2026 | A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… |