Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 546 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202620/7/2026
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202622/7/2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be…
AplazadaMedia (5.1)0.38%—Sourcecodester Pizzafy Ecommerce SystemAI19/7/202620/7/2026
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202620/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI19/7/202622/7/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202621/7/2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be…
AplazadaBaja (2)0.35%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202621/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202620/7/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI18/7/202622/7/2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI18/7/202621/7/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI17/7/202617/7/2026
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Pendiente de análisisCrítica (9.8)0.89%—Open Source GPT Researcher GPT ResearcherAI15/7/20266/10/2026
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
AnalizadaAlta (8.8)0.53%—F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+215/7/202611/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process,…
AplazadaBaja (2.1)0.49%—Sourcecodester Class AND Exam Timetabling SystemAI14/7/202614/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI14/7/202615/7/2026
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now…
AplazadaBaja (2.1)0.33%—Itsourcecode Electronic Judging SystemAI14/7/202615/7/2026
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /intrams/admin/add_judges.php. This manipulation of the argument fname causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI13/7/202614/7/2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unknown function of the file /edit_exam2.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI13/7/202615/7/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and…
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI13/7/202614/7/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subject causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed…
AplazadaBaja (2.1)0.42%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php…
AplazadaBaja (2)0.40%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI13/7/202615/7/2026
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
AplazadaBaja (1.9)0.37%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI9/7/20269/7/2026
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.