Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.27% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. | |
| Analizada | Crítica (9.8) | 0.77% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Analizada | Media (5.1) | 0.26% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Analizada | Media (5.4) | 0.27% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'. | |
| Analizada | Media (5.9) | 0.25% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1. |