Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.47% | — | California Courts Hearing Reminder ServiceAI | 9/7/2026 | 21/7/2026 | The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication. | |
| Analizada | Media (6.1) | 0.22% | — | Rems Medicine Reminder APP | 7/11/2025 | 17/6/2026 | Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the… | |
| Aplazada | Media (4.3) | 0.16% | — | Storepro Subscription Renewal Reminders FOR WoocommerceAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce subscriptions-renewal-reminders allows Cross Site Request Forgery.This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through <= 1.4.1. | |
| Analizada | Media (5.1) | 0.36% | — | Oretnom23 Task Reminder System | 14/1/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Section. The manipulation of the argument System Name leads to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (5.9) | 0.31% | — | Wpdevelop Email-remindersAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Email Reminders email-reminders allows Stored XSS.This issue affects Email Reminders: from n/a through <= 2.0.5. | |
| Aplazada | Media (6.4) | 0.35% | — | Email RemindersAI | 10/12/2024 | 17/6/2026 | The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (6.5) | 0.19% | — | Lucasgarcia Posts Reminder | 17/9/2024 | 17/6/2026 | The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Crítica (9.8) | 0.62% | — | Prestashop Abandoned Cart Reminder PRO | 20/3/2024 | 17/6/2026 | SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method. | |
| Modificada | Crítica (9.8) | 0.42% | — | Task Reminder System Project Task Reminder System | 28/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of this… | |
| Modificada | Alta (8.8) | 0.44% | — | Oretnom23 Task Reminder System | 27/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-243645… | |
| Modificada | Alta (8.8) | 0.44% | — | Oretnom23 Task Reminder System | 27/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_reminder. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of… | |
| Modificada | Media (5.4) | 0.52% | — | Task Reminder System Project Task Reminder System | 13/7/2023 | 17/6/2026 | A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter. | |
| Modificada | Media (5.4) | 0.34% | — | Teamlead Reminder | 16/6/2023 | 17/6/2026 | The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter. | |
| Modificada | Media (6.1) | 0.51% | — | Task Reminder System Project Task Reminder System | 21/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0 and classified as problematic. This issue affects some unknown processing of the file /classes/Users.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.66% | — | Task Reminder System Project Task Reminder System | 21/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Task Reminder System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.66% | — | Task Reminder System Project Task Reminder System | 21/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Task Reminder System 1.0. This affects an unknown part of the file /admin/reminders/manage_reminder.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 0.74% | — | Task Reminder System Project Task Reminder System | 18/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/?page=reminders/view_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 0.74% | — | Task Reminder System Project Task Reminder System | 18/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Task Reminder System 1.0. This issue affects some unknown processing of the file Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.66% | — | Click-reminder Project Click-reminder | 18/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in lierdakil click-reminder. It has been rated as critical. This issue affects the function db_query of the file src/backend/include/BaseAction.php. The manipulation leads to sql injection. The identifier of the patch is… | |
| Modificada | Baja (3.3) | 0.18% | — | Samsung Reminder | 7/10/2022 | 17/6/2026 | Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI. | |
| Modificada | Alta (8.8) | 0.60% | — | Genki Pre-publish Reminder Project Genki Pre-publish Reminder | 13/6/2022 | 17/6/2026 | The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings. | |
| Modificada | Media (5.3) | 0.62% | — | Samsung Reminder | 11/2/2022 | 17/6/2026 | Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely. | |
| Modificada | Alta (7.1) | 0.28% | — | Samsung Reminder | 10/1/2022 | 17/6/2026 | A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent. | |
| Modificada | Alta (10) | 2.6% | — | OpensuseRoaring Penguin Remind | 28/9/2015 | 17/6/2026 | Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name. | |
| Modificada | Alta (7.2) | 0.75% | — | Tukeva Password Reminder | 21/4/2010 | 16/6/2026 | TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection. |