Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Codeastro Online JOB PortalAI | 21/8/2026 | 26/8/2026 | A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB Portal SystemAI | 19/8/2026 | 25/8/2026 | A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 15/7/2026 | A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.50% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 14/7/2026 | A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 14/7/2026 | A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 14/7/2026 | 14/7/2026 | A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Codeastro Online JOB PortalAI | 1/6/2026 | 22/7/2026 | A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Codeastro Online JOB PortalAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.5) | 0.21% | — | Sourcecodester Online JOB Portal PhppdoAI | 27/4/2026 | 17/6/2026 | SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php. | |
| Aplazada | Media (5.5) | 0.51% | 💥 PoC | Codeastro Online JOB PortalAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Baja (2) | 0.33% | 💥 PoC | Codeastro Online JOB PortalAI | 26/4/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.38% | 💥 PoC | Codeastro Online JOB PortalAI | 13/4/2026 | 17/6/2026 | A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is… | |
| Analizada | Media (5.5) | 0.31% | — | Code-projects Online JOB Portal | 7/3/2024 | 17/6/2026 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1. | |
| Modificada | Crítica (9.8) | 0.57% | — | Code-projects Online JOB Portal | 7/3/2024 | 17/6/2026 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer." | |
| Analizada | Media (5.4) | 0.48% | — | Oretnom23 Online JOB Portal | 28/2/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Employer/EditProfile.php. The manipulation of the argument Address leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.4) | 0.52% | — | Janobe Online JOB Portal | 27/2/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Employer/ManageJob.php of the component Manage Job Page. The manipulation of the argument Qualification/Description leads to cross site… | |
| Analizada | Media (5.4) | 0.55% | — | Janobe Online JOB Portal | 27/2/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects unknown code of the file /Employer/ManageWalkin.php of the component Manage Walkin Page. The manipulation of the argument Job Title leads to cross site scripting. The attack can be initiated… | |
| Modificada | Media (4.8) | 0.50% | — | Projectworlds Online JOB Portal | 7/1/2024 | 17/6/2026 | A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Admin/News.php of the component Create News Page. The manipulation of the argument News with the input </title><scRipt>alert(0x00C57D)</scRipt> leads to cross site… | |
| Modificada | Crítica (9.8) | 0.83% | — | Projectworlds Online JOB Portal | 7/11/2023 | 17/6/2026 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname_email' parameter of the index.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.83% | — | Projectworlds Online JOB Portal | 7/11/2023 | 17/6/2026 | Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_uname' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 1.1% | — | Online JOB Portal Project Online JOB Portal | 23/9/2023 | 17/6/2026 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component. | |
| Modificada | Crítica (9.8) | 1.5% | — | Online JOB Portal Project Online JOB Portal | 23/9/2023 | 17/6/2026 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component. |