Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

5381 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.41%—Code-projects Employee Management SystemAI26/4/202617/6/2026
A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection. The attack is possible to be carried out remotely. The…
AnalizadaAlta (7.2)0.86%💥 PoCSanjay1313 Visitor Management System21/4/202617/6/2026
Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP webshell and achieve…
AplazadaMedia (5.1)0.53%—Navigate Content Management SystemAI21/4/202617/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript…
AplazadaMedia (5.4)0.29%—Apartment Visitors Management SystemAI20/4/202617/6/2026
Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitors.php or…
AplazadaAlta (7.5)0.49%—Apartment Visitors Management SystemAI20/4/202617/6/2026
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data.
AplazadaAlta (8.2)0.50%—Apartment Visitors Management SystemAI20/4/202617/6/2026
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database…
AplazadaCrítica (9.4)0.57%—Apartment Visitors Management SystemAI20/4/202617/6/2026
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database contents.
AplazadaMedia (5.5)0.47%—Rickxy Hospital Management SystemAI20/4/202617/6/2026
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic results in unrestricted upload. The attack can be executed remotely. The exploit has…
AplazadaMedia (5.5)0.41%—Projectsandprograms School Management SystemAI20/4/202617/6/2026
A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of the component HTTP GET Parameter Handler. The manipulation of the argument bus_id leads to sql injection. It is possible…
AplazadaCrítica (9.8)0.80%💥 PoCCodeastro Simple Attendance Management SystemAI17/4/202617/6/2026
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
AplazadaMedia (5.5)0.53%—Pratham-jaiswal Hotel Booking Management SystemAI17/4/20262/8/2026
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. Remote exploitation…
AplazadaCrítica (9.8)0.47%—Sourcecodester Vehicle Parking Area Management SystemAI16/4/202617/6/2026
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.
AplazadaAlta (7.2)0.45%—Sourcecodester Vehicle Parking Area Management SystemAI16/4/202617/6/2026
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.
AplazadaAlta (7.2)0.45%—Sourcecodester Vehicle Parking Area Management SystemAI16/4/202617/6/2026
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.
AplazadaAlta (7.2)0.45%—Sourcecodester Vehicle Parking Area Management SystemAI16/4/202617/6/2026
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.
AplazadaAlta (7.2)0.45%—Sourcecodester Vehicle Parking Area Management SystemAI16/4/202617/6/2026
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.
AplazadaMedia (6.1)0.18%—Manikandan580 School Management SystemAI14/4/202617/6/2026
In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.
AplazadaCrítica (9.8)0.29%—Manikandan580 School-management-systemAI14/4/202617/6/2026
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.
AplazadaMedia (6.1)0.18%—Manikandan580 School-management-systemAI14/4/202617/6/2026
In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter.
AplazadaCrítica (9.8)0.53%—Manikandan580 School Management SystemAI14/4/202617/6/2026
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information.
AplazadaCrítica (9.8)0.27%—Anirudhkannan Grocery Store Management SystemAI14/4/202617/6/2026
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.
AplazadaBaja (2.7)0.32%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Storage Unit Rental Management SystemAI14/4/202617/6/2026
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.