Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.31%—Admission AppmanagerAI17/8/202417/6/2026
The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaCrítica (9.8)1.2%💥 PoCOnline Admission System Project Online Admission System22/1/202417/6/2026
A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (8.8)0.76%—Admission Management System Project Admission Management System27/10/202317/6/2026
A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file student_avatar.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.65%—Online Student Admission System Project Online Student Admission System22/2/202317/6/2026
Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
ModificadaMedia (6.1)0.61%—Online Admission System Project Online Admission System11/8/202217/6/2026
A vulnerability classified as problematic has been found in SourceCodester Online Admission System. This affects an unknown part of the file /index.php. The manipulation of the argument student_add leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.54%—Online Student Admission System Project Online Student Admission System5/8/202217/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Student Admission System. Affected by this vulnerability is an unknown functionality of the file edit-profile.php of the component Student User Page. The manipulation with the input <script>alert(/xss/)</script> leads to cross site scripting.…
ModificadaMedia (6.1)0.68%—Online Admission System Project Online Admission System4/8/202217/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Online Admission System. Affected is an unknown function of the file index.php. The manipulation of the argument eid with the input 8</h3><script>alert(1)</script> leads to cross site scripting. It is possible to launch the attack…
ModificadaCrítica (9.8)0.87%—Online Admission System Project Online Admission System4/8/202217/6/2026
A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some unknown processing of the component GET Parameter Handler. The manipulation of the argument eid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaCrítica (9.8)0.87%—Online Admission System Project Online Admission System4/8/202217/6/2026
A vulnerability has been found in SourceCodester Online Admission System and classified as critical. This vulnerability affects unknown code of the component POST Parameter Handler. The manipulation of the argument shift leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)1.1%—Online Student Admission Project Online Student Admission5/4/202217/6/2026
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.
ModificadaCrítica (9.8)3.2%—Online Admission System Project Online Admissions System18/3/202217/6/2026
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.
ModificadaAlta (8.8)3.4%—Online Student Admission System Project Online Student Admission System26/10/202117/6/2026
Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.
ModificadaCrítica (9.8)2.2%—Online Student Admission System Project Online Student Admission System26/10/202117/6/2026
Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.
ModificadaCrítica (9.1)2.1%—SAP DmisSAP S4coreSapscore15/9/202117/6/2026
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to…
ModificadaAlta (7.2)3.0%—SAP AS Abap(dmis)SAP S4 Hana(dmis)10/11/202017/6/2026
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the…
ModificadaCrítica (9.8)19%💥 ExploitHP Intelligent Management Center Application Performance ManagerHP Intelligent Management Center Branch Intelligent Management SystemHP Intelligent Management Center Endpoint Admission DefenseHP Intelligent Management Center Network Traffic Analyzer+215/7/201617/6/2026
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections…
ModificadaMedia (5.4)0.27%—Hyonga Hanyang University Admissions16/10/201417/6/2026
The Hanyang University Admissions (aka kr.ac.hanyang.planner) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.1%—Cisco Network Admission Control Manager AND Server System Software18/4/201316/6/2026
SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095.
ModificadaMedia (5.8)0.53%—Cisco Network Admission Control28/2/201316/6/2026
The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka Bug ID CSCub24309.
ModificadaAlta (10)26%—HP Endpoint Admission DefenseHP Intelligent Management CenterHP User Access Manager11/7/201116/6/2026
Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to execute arbitrary code via a 0x0A0BF007 packet.
ModificadaAlta (10)2.6%—Cisco Network Admission Control16/4/200816/6/2026
Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error logs.
ModificadaAlta (10)4.1%—Cisco Network Admission Control Manager AND Server System Software4/1/200716/6/2026
Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.
ModificadaAlta (7.8)2.6%—Cisco Network Admission Control Manager AND Server System Software4/1/200716/6/2026
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.
ModificadaMedia (5)2.0%—Cisco Network Admission ControlCisco Network Admission Control Manager AND Server System Software29/8/200616/6/2026
The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the…
ModificadaMedia (5.7)0.64%—Cisco Network Admission Control Manager AND Server System Software31/12/200516/6/2026
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP scripts, a related issue to CVE-2005-4332.
Orbitaley — Vulnerabilidades