Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.44% | — | Fabian Online JOB Search Engine | 10/11/2025 | 17/6/2026 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation of the argument txtspecialization leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the argument txtusername results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 30/9/2026 | A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing manipulation of the argument txtjobID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.52% | — | Phpgurukul Local Services Search Engine Management System | 26/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.5) | 0.49% | — | Phpgurukul Local Services Search Engine Management System | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely.… | |
| Analizada | Media (5.5) | 0.51% | — | Phpgurukul Local Services Search Engine Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This vulnerability affects unknown code of the file /admin/edit-person-detail.php?editid=2. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The… | |
| Aplazada | Alta (7.1) | 0.29% | — | E1tekoap42 Search Engine Keywords HighlighterAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search engine keywords highlighter keywords-highlight-tool allows Reflected XSS.This issue affects Search engine keywords highlighter: from n/a through <= 0.1.3. | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul Local Services Search Engine Management System | 17/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.36% | — | Nesote Inout Search Engine AI Edition | 16/7/2023 | 17/6/2026 | A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Modificada | Media (6.1) | 0.62% | — | Local Service Search Engine Management System Project Local Service Search Engine Management System | 31/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input… | |
| Modificada | Media (4.8) | 0.93% | — | Local Services Search Engine Management System Project Local Services Search Engine Management System | 19/8/2021 | 17/6/2026 | A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields. | |
| Modificada | Media (4.9) | 0.84% | — | Local Services Search Engine Management System Project Local Services Search Engine Management System | 19/8/2021 | 17/6/2026 | A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database. | |
| Modificada | Crítica (9.8) | 25% | — | Local Services Search Engine Management System Project Local Services Search Engine Management System | 26/1/2021 | 17/6/2026 | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page. | |
| Modificada | Media (6.1) | 4.5% | — | Wpsolr-search-engine | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin wpsolr-search-engine v7.6 | |
| Modificada | Alta (7.5) | 1.1% | — | I-netsolution JOB Search Engine Script | 2/7/2010 | 16/6/2026 | SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | 2daybiz JOB Search Engine Script | 2/7/2010 | 16/6/2026 | SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM P8 Content EngineIBM P8 Content Search Engine | 30/6/2010 | 16/6/2026 | Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before FP1, as used in IBM FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), allows remote attackers to gain privileges via unknown vectors. NOTE:… | |
| Modificada | Media (4.3) | 1.5% | — | X10media MP3 Search Engine | 10/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id parameter to (3) templates/header1.php and (4) mp3/lyrics.php, key… | |
| Modificada | Alta (7.5) | 2.6% | — | Awscripts Gallery Search Engine | 26/6/2009 | 16/6/2026 | The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1. | |
| Modificada | Media (4.3) | 1.0% | — | Dansie Search Engine | 15/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.8% | — | Aleadsoft.com Search Engine Builder Professional | 22/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Altavista Search Engine | 28/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AltaVista search engine allows remote attackers to inject arbitrary web script or HTML via the text parameter to the default URI. | |
| Modificada | Media (6.1) | 0.44% | — | Google Custom Search Engine | 28/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this issue is disputed by the Google Security Team, who states that "Google does not provide the 'search.php' script referenced. When a user… | |
| Modificada | Alta (7.5) | 7.7% | — | Inout Scripts Inout Meta Search Engine | 1/6/2007 | 16/6/2026 | A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php. |