Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.28%—Sourcecodester Pizzafy E-commerce SystemAI3/6/202622/7/2026
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed…
AplazadaMedia (5.5)0.30%—Sourcecodester Online Food Ordering SystemAI3/6/202622/7/2026
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.21%—Sourcecodester Online Boat Reservation SystemAI3/6/202622/7/2026
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed…
AplazadaBaja (2.1)0.24%—Sourcecodester Human Resource ManagementAI2/6/202622/7/2026
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument employeeid leads to improper control of resource identifiers. The attack may be…
AplazadaBaja (2.1)0.20%—Itsourcecode Fees Management SystemAI2/6/202622/7/2026
A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.23%—Sourcecodester Pizzafy Ecommerce SystemAI2/6/202622/7/2026
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used.
AplazadaBaja (2.1)0.23%—Sourcecodester Pizzafy Ecommerce SystemAI2/6/202622/7/2026
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.20%—Itsourcecode Fees Management SystemAI2/6/202622/7/2026
A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
AplazadaBaja (2.1)0.27%—Itsourcecode Fees Management SystemAI2/6/202622/7/2026
A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.20%—Itsourcecode Fees Management SystemAI1/6/202622/7/2026
A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
AplazadaBaja (2.1)0.25%—Itsourcecode Fees Management SystemAI1/6/202622/7/2026
A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be…
AplazadaBaja (1.9)0.12%—Sourcecodester Customer Review APPAI1/6/202622/7/2026
A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service. The attack requires a local approach. The exploit…
AplazadaMedia (5.5)0.29%—Sourcecodester SEO Meta TAG ExtractorAI1/6/202622/7/2026
A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and…
AplazadaCrítica (10)0.44%💥 PoCCloudpirates Open Source Helm ChartsAIGithub ActionsAI1/6/202622/7/2026
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been…
AplazadaCrítica (10)0.44%💥 PoCCloudpirates Open Source Helm ChartsAIGithub ActionsAI1/6/202622/7/2026
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be…
AplazadaMedia (5.5)0.27%—Sourcecodester Computer Repair Shop Management SystemAI1/6/202622/7/2026
A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
AplazadaBaja (2.1)0.20%—Itsourcecode Content Management SystemAI1/6/202622/7/2026
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
AplazadaMedia (5.5)0.31%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.33%—Sourcecodester PET Grooming Management SoftwareAI1/6/202622/7/2026
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.26%—Itsourcecode Online House Rental SystemAI1/6/202622/7/2026
A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.26%—Itsourcecode Online House Rental SystemAI1/6/202622/7/2026
A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
AplazadaMedia (5.5)0.26%—Itsourcecode Online House Rental SystemAI1/6/202622/7/2026
A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the…
Orbitaley — Vulnerabilidades