Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.33% | — | Projectworlds Advanced Library Management System | 8/10/2025 | 17/6/2026 | A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_book.php. The manipulation of the argument image results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (1.9) | 0.26% | — | Projectworlds Advanced Library Management System | 8/10/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /edit_admin.php. The manipulation of the argument firstname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be… | |
| Modificada | Crítica (9.8) | 0.56% | — | Phpgurukul Online Library Management System | 16/9/2025 | 5/7/2026 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function | |
| Analizada | Crítica (9.8) | 0.56% | — | Phpgurukul Online Library Management System | 15/9/2025 | 17/6/2026 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php | |
| Analizada | Baja (2.1) | 0.39% | — | Khanakag-17 Library Management System | 1/9/2025 | 30/9/2026 | A vulnerability has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of the argument msg leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Modificada | Alta (7.1) | 0.31% | — | Phpgurukul Online Library Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack. | |
| Analizada | Baja (2) | 0.27% | — | Phpgurukul Online Library Management System | 14/7/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/student-history.php. The manipulation of the argument stdid leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Baja (2.1) | 0.36% | — | Phpgurukul Online Library Management System | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admin/student-history.php. The manipulation of the argument stdid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Library Management System | 9/7/2025 | 17/6/2026 | A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/profile_update.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.36% | — | Fabian Library Management System | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.32% | — | Slims Senayan Library Management System Bulian | 8/5/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php. | |
| Analizada | Media (6.5) | 0.32% | — | Slims Senayan Library Management System Bulian | 8/5/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/author.php. | |
| Analizada | Media (6.5) | 0.32% | — | Slims Senayan Library Management System Bulian | 8/5/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/item_status.php. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Slims Senayan Library Management SystemAI | 29/4/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php. | |
| Analizada | Media (5.3) | 0.50% | — | Angeljudesuarez Library Management System | 4/4/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.27% | — | Mingyuefusu Library Management System | 27/3/2025 | 17/6/2026 | A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.44% | — | Mingyuefusu Library Management System | 27/3/2025 | 17/6/2026 | A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection. The… | |
| Analizada | Baja (2.3) | 0.36% | — | Phpgurukul Online Library Management System | 7/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change-password.php. The manipulation of the argument email/phone number leads to weak password recovery. The attack can be launched… | |
| Analizada | Alta (7.2) | 0.54% | — | Slims Senayan Library Management System | 24/2/2025 | 17/6/2026 | SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component. | |
| Analizada | Media (6.7) | 0.63% | — | Slims Senayan Library Management System Bulian | 22/1/2025 | 17/6/2026 | A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php. | |
| Aplazada | Media (6.5) | 0.42% | — | Library Management System Manage E Digital Books LibraryAI | 12/12/2024 | 17/6/2026 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.8) | 0.44% | — | Library Management System Manage E Digital Books LibraryAI | 7/12/2024 | 17/6/2026 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Analizada | Media (6.9) | 0.70% | — | 1000projects Library Management System | 5/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /brains/stu.php. The manipulation of the argument useri leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.60% | — | 1000projects Library Management System | 5/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /showbook.php. The manipulation of the argument q leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.53% | — | Kitsada8621 Digital Library Management System | 29/8/2024 | 17/6/2026 | A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper output neutralization for logs. It is… |