Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.44% | — | Joomla Sexy Polling ReloadedAI | 28/8/2026 | 28/8/2026 | Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1 | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Online Polling System | 23/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (5.5) | 0.39% | — | Campcodes Online Polling System | 23/11/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Razormist Online Polling System | 17/9/2025 | 25/9/2026 | A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Baja (2) | 0.25% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.54% | — | Razormist Online Polling System | 30/8/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed from a remote location. The exploit is now public and may be used. | |
| Analizada | Media (4.9) | 0.52% | — | Bin-co Pollin | 19/2/2025 | 17/6/2026 | The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (6.1) | 0.34% | — | Bin-co Pollin | 19/2/2025 | 17/6/2026 | The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.9) | 0.93% | — | Fabian Online Polling | 12/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Online Polling 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file registeracc.php of the component Registration. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit… | |
| Modificada | Alta (7.5) | 2.3% | — | 2glux COM Sexypolling | 21/1/2014 | 17/6/2026 | SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the answer_id[] parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Dmxready Polling Booth Manager | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to execute arbitrary SQL commands via the QuestionID parameter in a results action. | |
| Modificada | Media (6.4) | 2.2% | — | Ajsquare Free Polling Script | 24/8/2009 | 16/6/2026 | AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 2.6% | — | Ajsquare Free Polling Script | 24/8/2009 | 16/6/2026 | AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php. | |
| Modificada | Alta (7.5) | 1.00% | — | Ajsquare Free Polling Script | 24/8/2009 | 16/6/2026 | SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter. |