Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.31%—Janobe Online Student File Management System17/9/202525/9/2026
A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be…
AnalizadaBaja (2.1)0.43%—Janobe Online Student File Management System15/9/202517/6/2026
A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been…
AnalizadaMedia (5.5)0.53%—Janobe Online Student File Management System15/9/202517/6/2026
A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
AnalizadaBaja (2.1)0.43%—Janobe Online Student File Management System15/9/202517/6/2026
A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and…
AnalizadaBaja (2.1)0.35%—Janobe Online Student File Management System15/9/202517/6/2026
A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.
AnalizadaMedia (5.5)0.43%—Janobe Online Student File Management System15/9/202530/9/2026
A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been released to the…
AnalizadaCrítica (9.8)0.88%—Nelzkie15 Complete File Management System23/2/202417/6/2026
A vulnerability has been found in SourceCodester Complete File Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Login Form. The manipulation of the argument username with the input…
AnalizadaCrítica (9.8)0.73%—Nelzkie15 Complete File Management System23/2/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Complete File Management System 1.0. Affected is an unknown function of the file users/index.php of the component Login Form. The manipulation of the argument username with the input torada%27+or+%271%27+%3D+%271%27+--+- leads to sql…
ModificadaMedia (6.1)0.43%—Carmelogarcia Employee Profile Management System12/1/202417/6/2026
A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. The manipulation of the argument pos_name leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.60%—Code-projects Employee Profile Management System12/1/202417/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (5.3)0.73%—Code-projects Employee Profile Management System12/1/202417/6/2026
A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be…
ModificadaMedia (6.1)0.43%—File Management System Project File Management System27/3/202317/6/2026
A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Edit User module.
ModificadaMedia (5.4)0.92%—School File Management System Project School File Management System23/6/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.
ModificadaMedia (6.1)0.90%—School File Management System Project School File Management System23/6/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.
ModificadaMedia (5.4)0.51%—Student Profile Management System Script Project Student Profile Management System Script12/4/201817/6/2026
PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php.
Orbitaley — Vulnerabilidades