Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | King-products Learning Management System King | 19/6/2026 | 19/8/2026 | Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Support Ticket Management SystemAI | 17/6/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Human Resources Management System | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this… | |
| Aplazada | Baja (2) | 0.21% | — | Codeastro Student Attendance Management SystemAI | 13/6/2026 | 23/7/2026 | A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.25% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is… | |
| Aplazada | Baja (2) | 0.20% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack may be launched remotely. The exploit… | |
| Aplazada | Baja (2) | 0.20% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.27% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester Onlne Examination AND Learning Management SystemAISourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026… | |
| Aplazada | Baja (2) | 0.20% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It is possible to launch the attack… | |
| Aplazada | Baja (2.1) | 0.23% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to improper… | |
| Aplazada | Baja (2.1) | 0.27% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.33% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator Login Endpoint. Performing a manipulation of the argument a_usr/a_pwd results in sql injection. The… | |
| Aplazada | Media (5.5) | 0.33% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. The exploit is… | |
| Aplazada | Baja (2.1) | 0.27% | — | Mohammed Eid35 Bank Management System SpringbootAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction Endpoint. Such… | |
| Aplazada | Media (5.5) | 0.28% | — | Sourcecodester Barangay Resident Profiling AND Information Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input password123 leads to use… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Hospital Management SystemAI | 8/6/2026 | 23/7/2026 | A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Hospital Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.27% | — | Itsourcecode Hospital Management SystemAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Leave Management SystemAI | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and… | |
| Aplazada | Media (5.3) | 0.19% | — | Codeastro Leave Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Leave Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been… |