Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.32% | — | Rashmindungrani Online-bankingAI | 7/12/2025 | 17/6/2026 | A vulnerability was found in RashminDungrani online-banking up to 2337ad552ea9d385b4e07b90e6f32d011b7c68a2. This affects an unknown part of the file /site/dist/auth_login.php. Performing manipulation of the argument Username results in sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.30% | — | G33kyrash Online-banking-systemAI | 17/11/2025 | 17/6/2026 | A vulnerability was detected in g33kyrash Online-Banking-System up to 12dbfa690e5af649fb72d2e5d3674e88d6743455. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit is now public and… | |
| Aplazada | Baja (1.9) | 0.27% | — | Langleyfcu Online Banking SystemAI | 6/10/2025 | 17/6/2026 | A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This impacts an unknown function of the file /customer_add_action.php of the component Add Customer Page. The manipulation of the argument First Name leads to cross site scripting. Remote exploitation of… | |
| Aplazada | Baja (2.1) | 0.35% | — | Langleyfcu Online Banking SystemAI | 29/9/2025 | 17/6/2026 | A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of the component Error Message Handler. Performing manipulation of the argument Error results in cross site… | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Online Banking System Project Online Banking System | 23/9/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php. | |
| Modificada | Media (6.5) | 0.97% | — | Online Banking System Project Online Banking System | 8/4/2022 | 17/6/2026 | Online Banking System in PHP v1 was discovered to contain multiple SQL injection vulnerabilities at /staff_login.php via the Staff ID and Staff Password parameters. | |
| Modificada | Crítica (9.8) | 1.2% | — | Online Banking System Project Online Banking System | 5/4/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Online Banking System Project Online Banking System | 15/3/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php. | |
| Modificada | Crítica (9.8) | 0.97% | — | Online Banking System Project Online Banking System | 21/1/2022 | 17/6/2026 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Overseaswtc Nexorone Online Banking System | 8/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in login.php in NexorONE Online Banking allow remote attackers to inject arbitrary web script or HTML via the (1) visitor_language parameter to register.php or (2) message parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | W2B Online Banking | 18/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilang parameter. | |
| Modificada | Alta (7.5) | 17% | — | W2B Online Banking | 11/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocPay parameter to DocPay.w2b. | |
| Modificada | Media (4.3) | 1.0% | — | W2B Online Banking | 11/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the adtype parameter, a different vector than CVE-2006-1980. | |
| Modificada | Baja (2.6) | 1.9% | — | W2B Online Banking | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter. | |
| Modificada | Media (5) | 1.3% | — | Itan Online Banking Security SystemAI | 2/9/2005 | 16/6/2026 | The iTAN Online-Banking Security System allows remote attackers to obtain TAN numbers via a man-in-the-middle (MITM) attack while the transaction is taking place, which facilitates a "phishing" attack. |