Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.31% | — | Janobe Online Student File Management System | 17/9/2025 | 25/9/2026 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be… | |
| Analizada | Baja (2.1) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.53% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2.1) | 0.35% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Media (5.5) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 30/9/2026 | A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been released to the… | |
| Analizada | Crítica (9.8) | 0.88% | — | Nelzkie15 Complete File Management System | 23/2/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Complete File Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Login Form. The manipulation of the argument username with the input… | |
| Analizada | Crítica (9.8) | 0.73% | — | Nelzkie15 Complete File Management System | 23/2/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Complete File Management System 1.0. Affected is an unknown function of the file users/index.php of the component Login Form. The manipulation of the argument username with the input torada%27+or+%271%27+%3D+%271%27+--+- leads to sql… | |
| Modificada | Media (6.1) | 0.43% | — | Carmelogarcia Employee Profile Management System | 12/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. The manipulation of the argument pos_name leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.60% | — | Code-projects Employee Profile Management System | 12/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (5.3) | 0.73% | — | Code-projects Employee Profile Management System | 12/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.1) | 0.43% | — | File Management System Project File Management System | 27/3/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Edit User module. | |
| Modificada | Media (5.4) | 0.92% | — | School File Management System Project School File Management System | 23/6/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php. | |
| Modificada | Media (6.1) | 0.90% | — | School File Management System Project School File Management System | 23/6/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php. | |
| Modificada | Media (5.4) | 0.51% | — | Student Profile Management System Script Project Student Profile Management System Script | 12/4/2018 | 17/6/2026 | PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php. |