Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.24% | — | Ousl-group-brinaries Brains School Student Management SystemAI | 31/5/2026 | 22/7/2026 | A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to improper control of resource… | |
| Aplazada | Media (5.5) | 0.41% | — | Ousl-group Brinarybrains School Student Management SystemAI | 31/5/2026 | 22/7/2026 | A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file application/controllers/Login.php of the component MY_Controller. Executing a manipulation of the argument role can lead to… | |
| Aplazada | Baja (2) | 0.21% | — | Bdtask Multi-store Inventory Management SystemAI | 31/5/2026 | 22/7/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate results in sql… | |
| Aplazada | Alta (8.8) | 0.32% | — | Projectworlds Gate Pass Management SystemAI | 30/5/2026 | 22/7/2026 | Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to… | |
| Aplazada | Baja (1.9) | 0.21% | — | Sambitraj Student-management-systemAI | 30/5/2026 | 22/7/2026 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Aplazada | Media (5.5) | 0.26% | — | Sambitraj Student-management-systemAI | 30/5/2026 | 22/7/2026 | A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of… | |
| Aplazada | Media (5.5) | 0.31% | 💥 PoC | Code-projects Student Details Management SystemAI | 30/5/2026 | 22/7/2026 | A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Courier Management SystemAI | 27/5/2026 | 24/7/2026 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Courier Management SystemAI | 27/5/2026 | 24/7/2026 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Project Management SystemAI | 26/5/2026 | 24/7/2026 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Performing a manipulation of the argument Remarks results in cross site scripting. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.50% | — | Sambitraj Student-management-systemAI | 26/5/2026 | 23/7/2026 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.41% | — | DAS Parking Parking Management SystemAI | 26/5/2026 | 23/7/2026 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public… | |
| Aplazada | Media (5.5) | 0.41% | — | DAS Parking Management SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.41% | — | Shenzhen Sixun Software Sixun Shanghui Group Business Management SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Leave Management SystemAI | 26/5/2026 | 23/7/2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.22% | — | Sourcecodester Student Grades Management SystemAI | 25/5/2026 | 23/7/2026 | A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Student Grades Management SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Student Grades Management SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be… | |
| Aplazada | Baja (2.1) | 0.35% | — | Sourcecodester Student Grades Management SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 25/5/2026 | 23/7/2026 | A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 25/5/2026 | 23/7/2026 | A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Employee Management SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the file /applyleave.php. Executing a manipulation of the argument ID can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2.1) | 0.43% | — | Yashpokharna2555 Student Management SystemAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file courseDel.php. The manipulation of the argument ID results in improper control of resource identifiers. The attack may be performed from remote. The exploit has… |