Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

5381 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.31%—A4m4 Student-management-systemAI1/6/202622/7/2026
A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to launch the attack remotely. The exploit…
AplazadaBaja (2.1)0.30%—A4m4 Student-management-systemAI1/6/202622/7/2026
A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component Admin Endpoint. This manipulation of the argument uid causes execution after redirect. It is possible to initiate the attack remotely.…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be…
AplazadaMedia (5.5)0.27%—Sourcecodester Computer Repair Shop Management SystemAI1/6/202622/7/2026
A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
AplazadaMedia (5.5)0.26%—Itsourcecode Online Blood Bank Management SystemAI1/6/202622/7/2026
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaMedia (5.5)0.27%—Itsourcecode Online Blood Bank Management SystemAI1/6/202622/7/2026
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
AplazadaBaja (2.1)0.25%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be…
AplazadaBaja (2)0.26%—Sourcecodester Water Billing Management SystemAI1/6/202622/7/2026
A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management Module. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The…
AplazadaMedia (5.5)0.37%—Sourcecodester Water Billing Management SystemAI1/6/202622/7/2026
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been…
AplazadaBaja (2.1)0.20%—Codeastro Ingredients Stock Management SystemAI1/6/202622/7/2026
A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been published and may…
AplazadaBaja (2)0.20%—Raisulislamg4 Student Management System BY PHPAI1/6/202622/7/2026
A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of the argument Message results in cross site scripting. The attack can be executed remotely.…
AplazadaMedia (5.5)0.26%—Raisulislamg4 Student Management System BY PHPAI1/6/202622/7/2026
A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The affected element is an unknown function of the file add_user_check.php of the component User Creation Handler. The manipulation of the argument role leads to sql injection. Remote…
AplazadaMedia (5.5)0.26%—Raisulislamg4 Student Management System BY PHPAI1/6/202622/7/2026
A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be…
AplazadaMedia (5.5)0.26%—Raisulislamg4 Student Management System BY PHPAI1/6/202622/7/2026
A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. This issue affects some unknown processing of the file login_check.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack may be…
AplazadaBaja (2.1)0.20%—Code-projects Online Hospital Management SystemAI1/6/202622/7/2026
A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit…
AplazadaMedia (5.5)0.26%—Code-projects Online Hospital Management SystemAI1/6/202622/7/2026
A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.27%—Code-projects Online Hospital Management SystemAI31/5/202622/7/2026
A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed…
AplazadaMedia (5.5)0.27%—Sourcecodester Hospitals Patient Records Management SystemAI31/5/202622/7/2026
A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the…
AplazadaMedia (5.5)0.27%—Sourcecodester Hospitals Patient Records Management SystemAI31/5/202622/7/2026
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public…
AplazadaBaja (2.1)0.21%—Bdtask Multi-store Inventory Management SystemAI31/5/202622/7/2026
A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted upload. The attack…
AplazadaBaja (2.1)0.24%💥 PoCCode-projects Visitor Management SystemAI31/5/202622/7/2026
A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AplazadaBaja (2.9)0.29%—Ousl-group-brinarybrains School Student Management SystemAI31/5/202622/7/2026
A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The manipulation of the…