Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Tushar-2223 Hotel Management SystemAI | 13/4/2026 | 17/6/2026 | A vulnerability was identified in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. Affected by this vulnerability is an unknown functionality of the file /admin/roomdelete.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Vehicle Showroom Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Vehicle Showroom Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCH_ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Vehicle Showroom Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has been made public and… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Vehicle Showroom Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipulation of the argument BRANCH_ID leads to cross site scripting. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Vehicle Showroom Management SystemAI | 10/4/2026 | 17/6/2026 | A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the argument BRANCH_ID can lead to cross site scripting. The attack may be launched remotely. The exploit has been published… | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 10/4/2026 | 17/6/2026 | A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of the argument toolname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Patient Record Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Patient Record Management SystemAI | 10/4/2026 | 17/6/2026 | A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Library Management SystemAI | 10/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Patient Record Management SystemAI | 9/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 9/4/2026 | 24/7/2026 | Se ha identificado una debilidad en itsourcecode Construction Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /borrowed_tool_report.PHP. Esta manipulación del argumento Home causa inyección SQL. Es posible iniciar el ataque de forma remota. El exploit ha sido puesto a… | |
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Pharmacy Product Management SystemAI | 8/4/2026 | 24/7/2026 | Una falla de seguridad ha sido descubierta en SourceCodester Pharmacy Product Management System 1.0. Esto afecta una parte desconocida del archivo add-sales.php del componente POST Parameter Gestor. Realizar una manipulación del argumento txtqty resulta en errores de lógica de negocio. Es posible iniciar el ataque… | |
| Analizada | Crítica (9.3) | 6.2% | — | Topsecgroup Tianxin Internet Behavior Management System | 7/4/2026 | 17/6/2026 | Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClass parameter containing shell metacharacters and output redirection. Attackers can exploit this… | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 7/4/2026 | 24/7/2026 | Se ha encontrado un fallo en itsourcecode Construction Management System 1.0. Esto afecta a una función desconocida del archivo /borrowedtool.PHP. La ejecución de una manipulación del argumento code puede conducir a una inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido publicado y puede ser… | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 6/4/2026 | 24/7/2026 | Una vulnerabilidad fue encontrada en itsourcecode Construction Management System 1.0. Esto afecta una parte desconocida del archivo /borrowed_tool.php del componente Gestor de Parámetros. La manipulación del argumento emp resulta en inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido hecho… | |
| Aplazada | Baja (2.1) | 0.45% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 24/7/2026 | Se determinó una vulnerabilidad en Cyber-III Student-Management-System hasta 1a938fa61e9f735078e9b291d2e6215b4942af3f. Se ve afectada una función desconocida del archivo /admin/class%20schedule/delete_batch.php del componente Class Schedule Deletion Endpoint. La ejecución de una manipulación del argumento batch puede… | |
| Aplazada | Baja (2.1) | 0.35% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 17/6/2026 | A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/submission/upload.php. Performing a manipulation of the argument File results in unrestricted upload. The attack can be… | |
| Aplazada | Media (5.5) | 0.41% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 17/6/2026 | A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible to launch the attack… | |
| Aplazada | Baja (1.9) | 0.35% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 17/6/2026 | A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown part of the file /admin/Add%20notice/add%20notice.php. This manipulation of the argument $_SERVER['PHP_SELF'] causes cross site scripting. It is possible to initiate the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 6/4/2026 | 17/6/2026 | A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.35% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 17/6/2026 | A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice.php. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting. The attack can be… | |
| Aplazada | Baja (1.9) | 0.35% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 17/6/2026 | A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of the component Admin Add Endpoint. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It… | |
| Aplazada | Media (5.5) | 0.47% | — | Cyber-iii Student-management-systemAI | 6/4/2026 | 17/6/2026 | A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva/update.php of the component HTTP POST Request Handler. This manipulation of the argument Name causes improper authorization. It is possible to… |