Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.32% | — | Janobe Online Reviewer System | 13/4/2026 | 17/6/2026 | Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Janobe Online Reviewer System | 13/4/2026 | 17/6/2026 | Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php. | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Online Reviewer SystemAI | 27/3/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.php. Such manipulation of the argument Description leads to cross site scripting. The attack may be performed from remote.… | |
| Analizada | Media (5.5) | 0.59% | — | Fabian Online Reviewer System | 22/2/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.21% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public… | |
| Analizada | Media (5.5) | 0.46% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack… | |
| Analizada | Baja (1.9) | 0.22% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.36% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.36% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection. The attack can be executed remotely. The exploit is publicly… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.5) | 0.40% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The exploit has been made… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Online Reviewer System | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Crítica (9.8) | 0.83% | — | Janobe Online Reviewer System | 9/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql… | |
| Modificada | Crítica (9.8) | 1.1% | — | Sourcecodester Online Reviewer System Project Sourcecodester Online Reviewer System | 20/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. | |
| Analizada | Crítica (9.8) | 7.2% | — | Janobe Online Reviewer System | 29/10/2021 | 17/6/2026 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters.. | |
| Analizada | Crítica (9.8) | 2.2% | — | Janobe Online Reviewer System | 14/4/2021 | 17/6/2026 | Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload. |