Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3977 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
AplazadaAlta (8.8)0.30%—Phpgurukul Online Course RegistrationAI13/4/202617/6/2026
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.
AplazadaBaja (2.1)0.38%💥 PoCCodeastro Online JOB PortalAI13/4/202617/6/2026
A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is…
AplazadaBaja (2.7)0.31%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php.
AnalizadaBaja (2.7)0.32%—Janobe Online Reviewer System13/4/202617/6/2026
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.
AnalizadaBaja (2.7)0.32%—Janobe Online Reviewer System13/4/202617/6/2026
Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.
AnalizadaCrítica (9.8)0.50%—Janobe Engineers Online Portal10/4/202617/6/2026
SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.
AnalizadaCrítica (9.8)0.50%—Itsourcecode Online Student Enrollment System10/4/202617/6/2026
A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.
AnalizadaCrítica (9.8)0.50%—Itsourcecode Online Student Enrollment System10/4/202617/6/2026
itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.
AnalizadaCrítica (9.8)0.50%—Itsourcecode Online Student Enrollment System10/4/202617/6/2026
A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropriate cleaning or…
AnalizadaCrítica (9.8)0.50%—Itsourcecode Online Student Enrollment System10/4/202617/6/2026
A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation.
AplazadaBaja (2.1)0.32%—Codeastro Online ClassroomAI10/4/202617/6/2026
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may…
Pendiente de análisisMedia (5.4)0.30%—Openstack SkylineAI10/4/202617/6/2026
OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.
AplazadaBaja (2.1)0.32%—Codeastro Online ClassroomAI10/4/202617/6/2026
A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a manipulation of the argument Q1 results in sql injection. Remote exploitation of the attack is possible. The…
AplazadaBaja (2.1)0.45%—Code-projects Online Library Management SystemAI10/4/202617/6/2026
A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made…
AplazadaBaja (1.9)0.35%—Code-projects Online Shoe StoreAI9/4/202624/7/2026
A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument product_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…
AplazadaBaja (1.9)0.35%—Code-projects Online Shoe StoreAI9/4/202624/7/2026
A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argument product_name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been…