Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

22.747 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.6)1.7%—Zohocorp Manageengine Adselfservice PlusAI22/9/202622/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Pendiente de análisisCrítica (9.8)4.6%—Zohocorp Manageengine Adselfservice PlusAI22/9/202623/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
AnalizadaAlta (7.8)0.07%—Qualcomm Package ManagerQualcomm Software Center22/9/20266/10/2026
Exposed dangerous function lead to privilege escalation via gRPC server.
AplazadaAlta (7.3)0.40%—Magepeople Taxi Booking Manager FOR WoocommerceAI22/9/202622/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.
AplazadaMedia (4.3)0.20%—Wpusermanager WP User ManagerAI22/9/202622/9/2026
The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that reaches…
AplazadaBaja (2)0.40%—Codeastro QR Code Attendance Management SystemAI20/9/202621/9/2026
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be…
AplazadaBaja (2.1)0.32%—Adithyayelloju Restaurant Management SystemAI20/9/202622/9/2026
A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/members/price results in sql injection. It is possible to launch the attack remotely.…
AplazadaBaja (2.1)0.33%—Adithyayelloju Restaurant-management-systemAI20/9/202621/9/2026
A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate…
AplazadaBaja (2.1)0.33%—Itsourcecode Leave Management SystemAI20/9/202622/9/2026
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.43%—Code-projects Internship Management SystemAI20/9/202621/9/2026
A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has…
AplazadaMedia (5.5)0.43%—Code-projects Internship Management SystemAI20/9/202622/9/2026
A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the…
AplazadaMedia (5.5)0.43%—Code-projects Internship Management SystemAI20/9/202621/9/2026
A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
AplazadaBaja (2)0.35%—Code-projects Assessment ManagementAI20/9/202624/9/2026
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been…
AplazadaBaja (1.9)0.37%—Code-projects Assessment ManagementAI20/9/202621/9/2026
A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.
AplazadaBaja (1.9)0.37%—Code-projects Assessment ManagementAI20/9/202621/9/2026
A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Reviewer Management SystemAI20/9/202622/9/2026
A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Reviewer Management SystemAI20/9/202621/9/2026
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Reviewer Management SystemAI20/9/202624/9/2026
A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack…
AplazadaMedia (5.5)0.45%—Nginxproxymanager Nginx Proxy ManagerAI20/9/202622/9/2026
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is…
AplazadaBaja (2.1)0.33%—Itsourcecode Leave Management SystemAI20/9/202621/9/2026
A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Reviewer Management SystemAI20/9/202622/9/2026
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The…
AplazadaBaja (2.1)0.51%—Gedelumbung HospitalmanagementAI18/9/202622/9/2026
A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function application/modules/global/controllers/password.php::simpan/application/modules/global/controllers/profil.php::simpan of the file…
AplazadaBaja (2.1)0.23%—Gedelumbung HospitalmanagementAI18/9/202618/9/2026
A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for…
Pendiente de análisisMedia (6.1)0.20%—IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI18/9/202622/9/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
Pendiente de análisisMedia (5.4)0.44%—Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI18/9/202621/9/2026
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,…