Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.24% | — | Perfect Support Ticketing AND Document Management SystemAI | 16/7/2026 | 18/7/2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Simple Online Leave Management SystemAI | 13/7/2026 | 13/7/2026 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 13/7/2026 | 15/7/2026 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Aplazada | Alta (8.6) | 0.45% | — | Library Management SystemAI | 13/7/2026 | 13/7/2026 | The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes. | |
| Aplazada | Baja (2.1) | 0.33% | — | Coderastro Simple Online Leave Management SystemAI | 13/7/2026 | 14/7/2026 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Media (5.1) | 0.33% | — | Akpali9 Attendance-management-systemAI | 12/7/2026 | 13/7/2026 | A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date results in cross site scripting. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Interview Management SystemAI | 9/7/2026 | 9/7/2026 | A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Codeastro Simple Online Leave Management SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Alta (8.7) | 0.56% | — | Prog MIS Prog Management SystemAI | 6/7/2026 | 6/7/2026 | Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Aplazada | Crítica (9.3) | 0.69% | — | Prog MIS Prog Management SystemAI | 6/7/2026 | 6/7/2026 | — | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 7/7/2026 | A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 6/7/2026 | A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 6/7/2026 | A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 6/7/2026 | 6/7/2026 | A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-visitor.php. Such manipulation of the argument remark leads to sql injection. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /paymentdischarge.php. This manipulation of the argument patientid causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /payment.php. The manipulation of the argument patientid results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Apartment Visitor Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the argument searchdata leads to sql injection. Remote exploitation of… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patientreport.php. Executing a manipulation of the argument editid can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientprofile.php. Performing a manipulation of the argument patientname results in sql injection. The attack can be initiated remotely. The exploit has been released… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege management. The attack can be executed… |