Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.42% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and… | |
| Modificada | Alta (7.5) | 0.45% | — | Oretnom23 Simple Online Book Store System | 14/11/2025 | 5/7/2026 | Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql. | |
| Analizada | Media (5.5) | 0.41% | — | Janobe Online Book Store | 30/8/2025 | 17/6/2026 | A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.3) | 0.51% | — | Angeljudesuarez Online Book Store Project | 20/9/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.3) | 0.54% | — | Oretnom23 Simple Online Book Store System | 21/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System 1.0. This affects an unknown part of the file admin_delete.php. The manipulation of the argument bookisbn leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Alta (8.4) | 0.24% | — | Angeljudesuarez Online Book Store Project | 17/6/2024 | 17/6/2026 | SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component. | |
| Modificada | Media (5.3) | 0.50% | — | Itsourcecode Online Book Store Project IN PHP AND Mysql With Source Code | 15/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_delete.php. The manipulation of the argument bookisbn leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.3) | 0.49% | — | Isourcecode Online Book Store Project IN PHP With Source Code | 15/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file /edit_book.php. The manipulation of the argument image leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.9) | 0.79% | — | Itsourcecode Online Book Store Project | 14/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file book.php. The manipulation of the argument bookisbn leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.9) | 0.64% | — | Itsourcecode Online Book Store Project | 14/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file bookPerPub.php. The manipulation of the argument pubid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.98% | — | Online Book Store Project Project Online Book Store Project | 28/9/2023 | 17/6/2026 | The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 1.5% | — | Projectworlds Online Book Store Project | 28/9/2023 | 17/6/2026 | Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application. | |
| Modificada | Crítica (9.8) | 0.76% | — | Online Book Store Project Project Online Book Store Project | 16/3/2023 | 17/6/2026 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Online Book Store Project Online Book Store | 24/2/2023 | 17/6/2026 | SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL. | |
| Modificada | Media (5.4) | 0.49% | — | Oretnom23 Simple Online Book Store System | 12/9/2022 | 17/6/2026 | In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS). | |
| Modificada | Crítica (9.8) | 0.55% | — | Simple Online Book Store System Project Simple Online Book Store System | 11/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. Affected by this vulnerability is an unknown functionality of the file /obs/bookPerPub.php. The manipulation of the argument bookisbn leads to sql injection. The attack can be launched remotely. The associated… | |
| Modificada | Crítica (9.8) | 0.63% | — | Simple Online Book Store System Project Simple Online Book Store System | 11/8/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System. Affected is an unknown function of the file /obs/book.php. The manipulation of the argument bookisbn leads to sql injection. It is possible to launch the attack remotely. VDB-206166 is the identifier… | |
| Modificada | Media (6.1) | 0.46% | — | Simple Online Book Store System Project Simple Online Book Store System | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Online Book Store System. It has been classified as problematic. Affected is an unknown function of the file /admin/edit.php. The manipulation of the argument eid leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.63% | — | Simple Online Book Store System Project Simple Online Book Store System | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Online Book Store and classified as critical. This issue affects some unknown processing of the file book.php. The manipulation of the argument book_isbn leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is… | |
| Modificada | Crítica (9.8) | 0.56% | — | Simple Online Book Store System Project Simple Online Book Store System | 11/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code of the file Admin_ add.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-206014 is the identifier assigned to this… | |
| Modificada | Media (6.5) | 0.53% | — | Projectworlds Online Book Store Project IN PHP | 22/12/2021 | 17/6/2026 | In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book. |