Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online Blood Bank Management SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.27% | — | Itsourcecode Online Blood Bank Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.25% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodestar Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be… | |
| Aplazada | Baja (2.1) | 0.25% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2) | 0.26% | — | Sourcecodester Water Billing Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management Module. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.37% | — | Sourcecodester Water Billing Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 31/5/2026 | 22/7/2026 | A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 31/5/2026 | 22/7/2026 | A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public… | |
| Aplazada | Alta (8.8) | 0.27% | — | MGB Opensource GuestbookAI | 30/5/2026 | 22/7/2026 | MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive… | |
| Aplazada | Media (6.1) | 0.26% | — | Sourcecodester Doctor Appointment SystemAI | 29/5/2026 | 21/7/2026 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php. | |
| Aplazada | Alta (7.3) | 0.49% | — | Sourcebans Material AdminAI | 28/5/2026 | 17/6/2026 | An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file. | |
| Aplazada | Alta (7.3) | 0.42% | — | Sourcebans Material AdminAI | 28/5/2026 | 17/6/2026 | An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Courier Management SystemAI | 27/5/2026 | 24/7/2026 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Courier Management SystemAI | 27/5/2026 | 24/7/2026 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.55% | — | Sourcecodester Edoc Doctor Appointment SystemAI | 26/5/2026 | 24/7/2026 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly… | |
| Aplazada | Baja (2.1) | 0.42% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 26/5/2026 | 24/7/2026 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote.… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 26/5/2026 | 24/7/2026 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Student Transcript Processing SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Student Transcript Processing SystemAI | 26/5/2026 | 23/7/2026 | A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Student Transcript Processing SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the argument studentId results in sql injection. The attack can be initiated remotely. The exploit is now public and… | |
| Analizada | Media (5.3) | 0.32% | — | Rexxars Eventsource-encoder | 26/5/2026 | 24/7/2026 | eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators… |