Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

5663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.54%—Sourcecodester Modern Loan Management SystemAI31/7/202631/8/2026
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.
AplazadaCrítica (9.8)0.42%—Sourcecodester Modern Loan Management SystemAI31/7/20261/10/2026
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.
AplazadaMedia (4.3)0.29%—Flippercode WP MapsAI31/7/202612/8/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.
AplazadaCrítica (9.8)0.80%—CodeigniterAI31/7/20268/9/2026
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible…
AplazadaAlta (7.5)0.64%—CodeigniterAI31/7/20268/9/2026
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes…
AplazadaCrítica (9.4)0.61%—CodeigniterAI31/7/20268/9/2026
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path.…
AplazadaMedia (4.8)0.17%—CodeigniterAI31/7/20268/9/2026
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may…
AnalizadaMedia (4.3)0.30%—IBM Devops DeployIBM Urbancode Deploy30/7/202610/8/2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access…
AnalizadaMedia (6.4)0.99%—Amazon Amplify Codegen UI30/7/202610/8/2026
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to…
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
AplazadaCrítica (9.8)0.32%—Code RO Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeatro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
AplazadaMedia (6.1)0.18%—Code-projects Blood SystemAI30/7/20261/10/2026
code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.
AplazadaAlta (7.3)0.34%—Sourcecodester Advocate Office Management SystemAI29/7/202630/7/2026
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate…
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
AplazadaAlta (7.3)0.20%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
AplazadaCrítica (9.8)0.32%—Sourcecodester Casap Automated Enrollment SystemAI29/7/20261/10/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.