Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.29%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaAlta (7.4)0.34%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaCrítica (9.1)0.40%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaMedia (6.5)0.35%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaMedia (5.4)0.21%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaMedia (5.3)0.33%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaMedia (6.5)0.44%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaMedia (5.4)0.23%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaCrítica (9.8)0.52%—Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI4/8/202626/8/2026
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
AplazadaCrítica (9.8)0.54%—Sourcecodester Modern Loan Management SystemAI31/7/202631/8/2026
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.
AplazadaCrítica (9.8)0.42%—Sourcecodester Modern Loan Management SystemAI31/7/20261/10/2026
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.
AplazadaCrítica (10)0.63%—Rich Source Dms+AI31/7/202626/8/2026
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
AplazadaAlta (7.3)0.34%—Sourcecodester Advocate Office Management SystemAI29/7/202630/7/2026
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate…
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
AplazadaMedia (6.1)0.19%—Sourcecodester Fantastic Blog CMSAI29/7/20265/10/2026
Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.
AplazadaCrítica (9.8)0.51%—Regularlabs SourcererAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI22/7/202622/7/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI21/7/202622/7/2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI21/7/202622/7/2026
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and…