Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | CAR Driving School Management System Project CAR Driving School Management System | 28/2/2022 | 17/6/2026 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ingenious School Management System Project Ingenious School Management System | 7/11/2017 | 17/6/2026 | /view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request. | |
| Modificada | Alta (8.8) | 3.9% | 💥 Exploit | Ingenious School Management System Project Ingenious School Management System | 29/10/2017 | 17/6/2026 | my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. | |
| Modificada | Alta (8.8) | 2.7% | 💥 Exploit | Dasinfomedia School Management System | 28/9/2017 | 17/6/2026 | Mojoomla School Management System for WordPress allows SQL Injection via the id parameter. | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Caloris Planitia Technologies E-school Management System | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter. |