Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 1.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 22/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. | |
| Pendiente de análisis | Crítica (9.8) | 4.6% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 23/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Package ManagerQualcomm Software Center | 22/9/2026 | 6/10/2026 | Exposed dangerous function lead to privilege escalation via gRPC server. | |
| Aplazada | Alta (7.3) | 0.40% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 22/9/2026 | 22/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpusermanager WP User ManagerAI | 22/9/2026 | 22/9/2026 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that reaches… | |
| Aplazada | Baja (2) | 0.40% | — | Codeastro QR Code Attendance Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Adithyayelloju Restaurant Management SystemAI | 20/9/2026 | 22/9/2026 | A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/members/price results in sql injection. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Adithyayelloju Restaurant-management-systemAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Leave Management SystemAI | 20/9/2026 | 22/9/2026 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 21/9/2026 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 22/9/2026 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Internship Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.37% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 21/9/2026 | A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (1.9) | 0.37% | — | Code-projects Assessment ManagementAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 22/9/2026 | A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 24/9/2026 | A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 20/9/2026 | 22/9/2026 | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Leave Management SystemAI | 20/9/2026 | 21/9/2026 | A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 22/9/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2.1) | 0.51% | — | Gedelumbung HospitalmanagementAI | 18/9/2026 | 22/9/2026 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function application/modules/global/controllers/password.php::simpan/application/modules/global/controllers/profil.php::simpan of the file… | |
| Aplazada | Baja (2.1) | 0.23% | — | Gedelumbung HospitalmanagementAI | 18/9/2026 | 18/9/2026 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI | 18/9/2026 | 22/9/2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (5.4) | 0.44% | — | Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI | 18/9/2026 | 21/9/2026 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,… |