Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.22% | 💥 PoC | Grocery Store Management System Using PHP AND Mysql PhpmyadminAI | 25/6/2026 | 26/6/2026 | GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | |
| Aplazada | Crítica (9.2) | 0.64% | — | VvvebAIPhpmyadminAI | 6/5/2026 | 17/6/2026 | Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain unrestricted read… | |
| Aplazada | Media (6.4) | 0.42% | — | PhpmyadminAI | 23/1/2025 | 17/6/2026 | An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS. | |
| Aplazada | Media (6.4) | 0.41% | — | PhpmyadminAI | 23/1/2025 | 17/6/2026 | An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab. | |
| Modificada | Media (5.4) | 1.2% | — | Phpmyadmin | 13/2/2023 | 17/6/2026 | In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface. | |
| Modificada | Crítica (9.8) | 1.7% | — | Phpmyadmin | 26/1/2023 | 9/7/2026 | SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php. | |
| Modificada | Media (4.8) | 0.84% | — | Puvox WP Phpmyadmin | 22/8/2022 | 17/6/2026 | The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 1.3% | — | Phpmyadmin | 10/3/2022 | 17/6/2026 | PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section. | |
| Modificada | Media (6.1) | 7.9% | 💥 Exploit | Phpmyadmin | 22/1/2022 | 17/6/2026 | An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection. | |
| Modificada | Media (4.3) | 0.74% | — | Phpmyadmin | 22/1/2022 | 17/6/2026 | An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances. | |
| Modificada | Alta (8.8) | 1.5% | — | Phpmyadmin | 4/11/2020 | 17/6/2026 | phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents. | |
| Modificada | Crítica (9.8) | 67% | 💥 Exploit | PhpmyadminOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 10/10/2020 | 17/6/2026 | An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query. | |
| Modificada | Media (6.1) | 1.9% | — | PhpmyadminOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 10/10/2020 | 17/6/2026 | phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. | |
| Modificada | Media (6.1) | 2.4% | 💥 Exploit | Phpmyadmin | 31/3/2020 | 17/6/2026 | phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable. | |
| Modificada | Media (5.4) | 1.4% | — | PhpmyadminDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 22/3/2020 | 17/6/2026 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into… | |
| Modificada | Alta (8) | 1.8% | — | PhpmyadminDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 22/3/2020 | 17/6/2026 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or… | |
| Modificada | Alta (8) | 2.4% | — | PhpmyadminFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 22/3/2020 | 17/6/2026 | In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim… | |
| Modificada | Crítica (9.1) | 3.7% | — | Getbutterfly Portable-phpmyadmin | 18/2/2020 | 16/6/2026 | WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities | |
| Modificada | Crítica (9.1) | 2.8% | — | Portable Phpmyadmin Project Portable Phpmyadmin | 27/1/2020 | 16/6/2026 | WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability | |
| Modificada | Alta (8.8) | 39% | 💥 Exploit | PhpmyadminSuse Linux Enterprise ServerDebian Linux | 9/1/2020 | 17/6/2026 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server. | |
| Modificada | Crítica (9.8) | 2.6% | — | PhpmyadminDebian Linux | 6/12/2019 | 17/6/2026 | phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | PhpmyadminOpensuse Backports SLEFedoraproject FedoraOpensuse Leap | 22/11/2019 | 17/6/2026 | An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. | |
| Modificada | Media (6.5) | 10% | 💥 Exploit | PhpmyadminFedoraproject Fedora | 13/9/2019 | 17/6/2026 | A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. | |
| Modificada | Media (6.5) | 19% | 💥 Exploit | Phpmyadmin | 5/6/2019 | 17/6/2026 | An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a… | |
| Modificada | Crítica (9.8) | 4.1% | — | Phpmyadmin | 5/6/2019 | 17/6/2026 | An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. |