Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.80% | — | Remyandrade User Registration AND Login System | 2/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument user leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.60% | — | Remyandrade User Registration AND Login System | 1/12/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument first_name leads to cross site scripting. The attack can be launched… | |
| Modificada | Media (6.1) | 0.61% | — | Remyandrade User Registration AND Login System | 1/12/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 1.0. Affected is an unknown function of the file /endpoint/delete-user.php. The manipulation of the argument user leads to cross site scripting. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 1.3% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 2/6/2022 | 17/6/2026 | EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Crítica (9.8) | 2.5% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 26/1/2021 | 17/6/2026 | EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution. | |
| Modificada | Media (5.4) | 0.60% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers. | |
| Modificada | Media (6.1) | 0.81% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the… | |
| Modificada | Alta (7.5) | 1.1% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 30/12/2020 | 9/7/2026 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page. | |
| Modificada | Media (6.1) | 0.97% | — | Egavilanmedia User Registration AND Login System With Admin Panel | 23/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0. |