Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.34% | — | Facebook-julykringcadayona Student Information System | 17/9/2025 | 25/9/2026 | A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of the argument level_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Yordam Informatics Yordam Library Automation SystemAI | 17/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection. This issue affects Yordam Library Automation System: from 21.5 & 21.6 before 21.7. | |
| Aplazada | Media (4.7) | 0.24% | — | Zirve Information Technologies INC Zirve NovaAI | 17/9/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS). This issue affects Zirve Nova: from 235 through 20250131. | |
| Aplazada | Alta (8.6) | 0.33% | — | E1 InformaticsAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web Application allows SQL Injection. This issue affects Web Application: through 20250916. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE… | |
| Aplazada | Media (4.3) | 0.22% | 💥 PoC | Ubit Information Technologies StoysAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS). This issue affects STOYS: from 2 before 20250916. | |
| Analizada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 30/9/2026 | A vulnerability was determined in itsourcecode Baptism Information Management System 1.0. Affected is an unknown function of the file /listbaptism.php. This manipulation of the argument bapt_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.3) | 0.12% | — | IBM Qradar Security Information AND Event Manager | 14/9/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment. | |
| Analizada | Media (6.8) | 0.21% | — | IBM Security Verify Information Queue | 10/9/2025 | 17/6/2026 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges. | |
| Analizada | Alta (7.5) | 0.19% | — | IBM Security Verify Information Queue | 10/9/2025 | 17/6/2026 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (6.5) | 0.37% | — | IBM Security Verify Information Queue | 10/9/2025 | 17/6/2026 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handling of special characters that could lead to uncontrolled resource consumption. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 9/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 6/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (6.7) | 0.14% | — | IBM Transformation Advisor | 3/9/2025 | 17/6/2026 | IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly… | |
| Analizada | Media (5.5) | 0.41% | — | Facebook-julykringcadayona Student Information System | 30/8/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Itsourcecode Student Information Management System | 29/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and… | |
| Analizada | Media (5.5) | 0.49% | — | Nelzkie15 Human Resource Information System | 26/8/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the file /Superadmin_Dashboard/process/editemployee_process.php. Such manipulation of the argument employee_file201 leads to unrestricted upload. The attack may be launched… | |
| Analizada | Media (5.5) | 0.49% | — | Nelzkie15 Human Resource Information System | 26/8/2025 | 17/6/2026 | A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin_Dashboard/process/editemployee_process.php. This manipulation of the argument employee_file201 causes unrestricted upload. The attack may be initiated remotely.… | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges. |