Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Employee Management SystemAI | 26/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of the argument pwd results in sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Alta (7.2) | 0.86% | 💥 PoC | Sanjay1313 Visitor Management System | 21/4/2026 | 17/6/2026 | Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP webshell and achieve… | |
| Aplazada | Media (5.1) | 0.53% | — | Navigate Content Management SystemAI | 21/4/2026 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript… | |
| Aplazada | Media (5.4) | 0.29% | — | Apartment Visitors Management SystemAI | 20/4/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitors.php or… | |
| Aplazada | Alta (7.5) | 0.49% | — | Apartment Visitors Management SystemAI | 20/4/2026 | 17/6/2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data. | |
| Aplazada | Alta (8.2) | 0.50% | — | Apartment Visitors Management SystemAI | 20/4/2026 | 17/6/2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database… | |
| Aplazada | Crítica (9.4) | 0.57% | — | Apartment Visitors Management SystemAI | 20/4/2026 | 17/6/2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database contents. | |
| Aplazada | Media (5.5) | 0.47% | — | Rickxy Hospital Management SystemAI | 20/4/2026 | 17/6/2026 | A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic results in unrestricted upload. The attack can be executed remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectsandprograms School Management SystemAI | 20/4/2026 | 17/6/2026 | A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of the component HTTP GET Parameter Handler. The manipulation of the argument bus_id leads to sql injection. It is possible… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Codeastro Simple Attendance Management SystemAI | 17/4/2026 | 17/6/2026 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php. | |
| Aplazada | Media (5.5) | 0.53% | — | Pratham-jaiswal Hotel Booking Management SystemAI | 17/4/2026 | 2/8/2026 | A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. Remote exploitation… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php. | |
| Aplazada | Media (6.1) | 0.18% | — | Manikandan580 School Management SystemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter. | |
| Aplazada | Crítica (9.8) | 0.29% | — | Manikandan580 School-management-systemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter. | |
| Aplazada | Media (6.1) | 0.18% | — | Manikandan580 School-management-systemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Manikandan580 School Management SystemAI | 14/4/2026 | 17/6/2026 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information. | |
| Aplazada | Crítica (9.8) | 0.27% | — | Anirudhkannan Grocery Store Management SystemAI | 14/4/2026 | 17/6/2026 | Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter. | |
| Aplazada | Baja (2.7) | 0.32% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php. |