Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.58%—Oretnom23 Online Diagnostic LAB Management System7/3/202417/6/2026
An issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted POST request using the id, email, password, and cpass parameters.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System17/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System17/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php.
ModificadaCrítica (9.8)0.79%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System16/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.
ModificadaCrítica (9.8)0.68%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System9/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System7/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System7/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System3/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System3/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System2/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
ModificadaAlta (7.2)0.86%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System2/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message.
ModificadaAlta (7.2)0.76%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System2/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment.
ModificadaAlta (8.8)0.87%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System2/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
ModificadaAlta (7.2)0.78%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System1/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.
ModificadaAlta (7.2)0.78%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System1/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php.
ModificadaAlta (7.2)0.78%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System1/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.
ModificadaAlta (7.2)0.78%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System1/11/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
ModificadaCrítica (9.8)1.2%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System14/10/202217/6/2026
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.
ModificadaAlta (7.2)1.3%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System13/10/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.2)1.1%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System13/10/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.2)0.87%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System7/10/202217/6/2026
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
ModificadaAlta (7.2)0.87%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System7/10/202217/6/2026
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
ModificadaAlta (7.2)0.87%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System7/10/202217/6/2026
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /diagnostic/edittest.php.
ModificadaAlta (7.2)1.3%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System7/10/202217/6/2026
An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaCrítica (9.8)1.1%—Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System26/8/202217/6/2026
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"