Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

5381 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.45%—Code-projects Employee Management SystemAI25/5/202623/7/2026
A vulnerability has been found in code-projects Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /empproject.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaBaja (2.1)0.45%—Code-projects Employee Management SystemAI25/5/202623/7/2026
A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /changepassemp.php. Executing a manipulation of the argument ID can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may…
AplazadaBaja (2.1)0.45%—Code-projects Employee Management SystemAI25/5/202623/7/2026
A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the file /myprofileup.php. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.45%—Code-projects Employee Management SystemAI25/5/202623/7/2026
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument ID leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
AplazadaBaja (2.1)0.45%—Code-projects Employee Management SystemAI25/5/202623/7/2026
A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the file /eloginwel.php. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be…
AplazadaMedia (5.5)0.41%—Sourcecodester Hospitals Patient Records Management SystemAI24/5/202623/7/2026
A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage_history.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the…
AplazadaMedia (5.5)0.41%—Sourcecodester Hospitals Patient Records Management SystemAI24/5/202623/7/2026
A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_patient_history. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been…
AplazadaBaja (2.1)0.32%—Sourcecodester Hospitals Patient Records Management SystemAI23/5/202623/7/2026
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the…
AplazadaCrítica (9.4)0.45%—Frappe Learning Management SystemAI20/5/202623/7/2026
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.
AplazadaCrítica (9.1)0.65%—Lalanachami Pharmacy Management SystemAI19/5/202624/7/2026
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via…
AplazadaCrítica (9.8)0.63%—Lalanachami Pharmacy Management SystemAI19/5/202624/7/2026
The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body
AplazadaAlta (7.3)0.53%—Offline Hospital Management SystemAI18/5/202617/6/2026
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system…
AplazadaMedia (5.5)0.41%—Projectworlds Hospital-management-system-in-phpAI18/5/202617/6/2026
A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be…
AplazadaMedia (5.1)0.21%—Zenar Content Management SystemAI17/5/202617/6/2026
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized…
AplazadaMedia (5.1)0.24%—Queue Management SystemAI16/5/202629/9/2026
Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing…
AplazadaCrítica (9.8)0.47%—Beauty Parlour Management SystemAI8/5/202617/6/2026
Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
AplazadaAlta (7.3)0.81%💥 ExploitPrison Management SystemAI8/5/202617/6/2026
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.
AplazadaMedia (5.5)0.41%—Codeastro Leave Management SystemAI8/5/202617/6/2026
A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
AplazadaMedia (5.4)0.23%—Phpgurukal Hospital Management SystemAI7/5/20265/7/2026
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in…
AplazadaMedia (6.5)0.43%—Codeastro Membership Management SystemAI7/5/20265/7/2026
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.
AplazadaBaja (2.1)0.32%—Itsourcecode Courier Management SystemAI5/5/202617/6/2026
A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The manipulation of the argument ids leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
AplazadaBaja (2.1)0.32%—Sourcecodester Web-based Pharmacy Product Management SystemAI4/5/202617/6/2026
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and…
AplazadaMedia (6.9)0.41%—Shandong Hoteam Software PDM Product Data Management SystemAI4/5/202617/6/2026
A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely.…
AplazadaBaja (2.1)0.32%—Code-projects GYM Management System IN PHPAIMicrosoft Windows NTAI4/5/202617/6/2026
A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
AplazadaMedia (5.5)0.41%—Acrel Electrical Ecems Enterprise Microgrid Energy Efficiency Management SystemAI3/5/202617/6/2026
A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. Executing a manipulation of the argument fCircuitids can lead to sql injection. The attack can be launched…