Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.74%—Food Ordering Website Project Food Ordering Website17/9/202317/6/2026
A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (4.8)0.58%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website28/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack may be initiated…
ModificadaAlta (7.5)0.60%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin_class.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.79%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been classified as critical. This affects an unknown part of the file watch.php. The manipulation of the argument code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)0.65%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability was found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file upload.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may…
ModificadaAlta (7.5)0.66%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability has been found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file signup.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.74%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website6/4/202317/6/2026
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to…
ModificadaCrítica (9.8)0.73%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website2/4/202317/6/2026
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/fields/manage_field.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may…
ModificadaCrítica (9.8)0.87%—Institutional Management Website Project Institutional Management Website8/2/202317/6/2026
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
ModificadaCrítica (9.8)0.95%—Institutional Management Website Project Institutional Management Website8/2/202317/6/2026
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
ModificadaAlta (8.8)0.66%—Challenge Website Project Challenge Website28/12/202217/6/2026
A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The name of the patch is f1644b1d3502e5aa5284f31ea80d2623817f4d42. It is recommended to apply a patch to fix this issue. The identifier VDB-216989 was…
ModificadaMedia (6.1)0.47%—Ecommerce-website Project Ecommerce-website5/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
ModificadaAlta (8.8)1.4%—Klik-socialmediawebsite Project Klik-socialmediawebsite22/11/202217/6/2026
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
ModificadaCrítica (9.8)2.7%—Simple College Website Project Simple College Website22/9/202217/6/2026
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.
ModificadaMedia (6.1)0.77%—Simple College Website Project Simple College Website22/9/202217/6/2026
Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
ModificadaCrítica (9.8)1.8%—Simple College Website Project Simple College Website22/9/202217/6/2026
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (5.4)0.54%—Simple Food Website Project Simple Food Website23/5/202217/6/2026
In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.
ModificadaAlta (8.8)0.55%—Simple Food Website Project Simple Food Website23/5/20229/7/2026
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.
ModificadaMedia (5.4)0.56%—E-commerce Website Project E-commerce Website3/5/202217/6/2026
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.
ModificadaCrítica (9.8)3.6%—Ecommerce-website Project Ecommerce-website8/4/202217/6/2026
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)2.7%—Ecommerce-website Project Ecommerce-website8/4/202217/6/2026
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (4.8)0.99%—Ecommerce-website Project Ecommerce-website4/4/202217/6/2026
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
ModificadaAlta (8.8)1.7%—Ecommerce-website Project Ecommerce-website4/4/202217/6/2026
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
ModificadaCrítica (9.8)1.3%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website2/3/202217/6/2026
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
ModificadaAlta (8.1)4.2%—Simple College Website Project Simple College Website21/1/202217/6/2026
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.