Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.51% | — | Angeljudesuarez Online Book Store Project | 20/9/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (8.4) | 0.24% | — | Angeljudesuarez Online Book Store Project | 17/6/2024 | 17/6/2026 | SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component. | |
| Modificada | Media (5.3) | 0.50% | — | Itsourcecode Online Book Store Project IN PHP AND Mysql With Source Code | 15/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_delete.php. The manipulation of the argument bookisbn leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.3) | 0.49% | — | Isourcecode Online Book Store Project IN PHP With Source Code | 15/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file /edit_book.php. The manipulation of the argument image leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.9) | 0.79% | — | Itsourcecode Online Book Store Project | 14/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file book.php. The manipulation of the argument bookisbn leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.9) | 0.64% | — | Itsourcecode Online Book Store Project | 14/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file bookPerPub.php. The manipulation of the argument pubid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.98% | — | Online Book Store Project Project Online Book Store Project | 28/9/2023 | 17/6/2026 | The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (8.8) | 1.5% | — | Projectworlds Online Book Store Project | 28/9/2023 | 17/6/2026 | Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application. | |
| Modificada | Crítica (9.8) | 0.76% | — | Online Book Store Project Project Online Book Store Project | 16/3/2023 | 17/6/2026 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Online Book Store Project Online Book Store | 24/2/2023 | 17/6/2026 | SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL. | |
| Modificada | Media (6.5) | 0.53% | — | Projectworlds Online Book Store Project IN PHP | 22/12/2021 | 17/6/2026 | In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Online Book Store Project IN PHP | 22/12/2021 | 17/6/2026 | Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Crítica (9.8) | 3.0% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.6% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Projectworlds Online Book Store Project IN PHP | 6/5/2021 | 17/6/2026 | SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Online Book Store Project Online Book Store | 9/4/2021 | 17/6/2026 | SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | |
| Modificada | Alta (7.5) | 1.5% | — | Online Book Store Project Online Book Store | 17/2/2021 | 17/6/2026 | The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases. | |
| Modificada | Crítica (9.8) | 2.0% | — | Online Book Store Project Online Book Store | 31/8/2020 | 17/6/2026 | In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access. |