Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.54% | — | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.55% | — | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (2) | 0.44% | — | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Analizada | Baja (2) | 0.46% | — | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/testimonials/manage.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Baja (2) | 0.43% | — | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2) | 0.40% | 💥 PoC | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.6) | 0.42% | — | Wow-company Hover-effectsAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wow-Company Hover Effects hover-effects allows SQL Injection.This issue affects Hover Effects: from n/a through <= 2.1.2. | |
| Analizada | Media (6.9) | 0.66% | — | Phpgurukul Company Visitor Management System | 27/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affected is an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Company Visitor Management System | 27/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Company Visitor Management System | 15/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. The manipulation of the argument fullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.64% | — | Phpgurukul Company Visitor Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. This affects an unknown part of the file /department.php. The manipulation of the argument departmentname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul Company Visitor Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument adminname/mobilenumber leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.73% | — | Phpgurukul Company Visitor Management System | 6/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /visitor-detail.php. The manipulation of the argument editid/remark leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (6.1) | 0.30% | — | Torrahclef Company Website CMS | 16/4/2025 | 17/6/2026 | SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services. | |
| Analizada | Crítica (9.8) | 0.61% | — | Torrahclef Company Website CMS | 16/4/2025 | 17/6/2026 | SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio. | |
| Analizada | Crítica (9.8) | 0.61% | — | Torrahclef Company Website CMS | 16/4/2025 | 17/6/2026 | SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services. | |
| Analizada | Media (5.3) | 0.32% | — | Kennifrog Company Financial Management System | 6/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection. The attack can be… | |
| Aplazada | Media (5.4) | 0.18% | — | Wow-company Float MenuAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Float menu float-menu allows Cross Site Request Forgery.This issue affects Float menu: from n/a through <= 6.1.2. | |
| Analizada | Media (6.9) | 2.4% | 💥 Exploit | Phpgurukul Company Visitor Management System | 18/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Sign In. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The… | |
| Aplazada | Alta (7.5) | 0.37% | — | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS ApplicationAI | 4/3/2025 | 17/6/2026 | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history,… | |
| Analizada | Media (4.8) | 0.29% | — | Wow-company Counter BOX | 1/3/2025 | 17/6/2026 | The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.19% | — | Tencent Technology Beijing Company Limited Tencent Microvision IOSAI | 27/2/2025 | 17/6/2026 | An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (5.5) | 0.19% | — | Merchants Union Consumer Finance Company Limited Merchants Union Finance IOSAI | 27/2/2025 | 17/6/2026 | An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Alta (7.5) | 0.61% | — | Wow-company Calculator BuilderAI | 22/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Calculator Builder calculator-builder allows PHP Local File Inclusion.This issue affects Calculator Builder: from n/a through <= 1.6.2. | |
| Analizada | Media (5.4) | 0.31% | — | Wow-company Modal Window | 20/2/2025 | 17/6/2026 | The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 6.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |