Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Construction Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Construction Management System 1.0. This vulnerability affects unknown code of the file /execute1.php. Such manipulation of the argument code leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Construction Management SystemAI | 27/4/2026 | 17/6/2026 | A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /execute.php. This manipulation of the argument code causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Codepanda Source Canteen Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in CodePanda Source canteen_management_system 1.0. Affected by this issue is some unknown functionality of the file /api/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.3) | 0.41% | — | Baomidou Dynamic-datasourceAI | 26/4/2026 | 17/6/2026 | A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the component… | |
| Aplazada | Alta (8.2) | 0.66% | — | Ossn Open Source Social NetworkAI | 24/4/2026 | 17/6/2026 | Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file size on disk may be… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Analizada | Media (5.4) | 0.17% | 💥 PoC | Oracle Peoplesoft Enterprise HCM Human Resources | 21/4/2026 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human… | |
| Aplazada | Media (6.4) | 0.26% | — | Image Source Control LiteAI | 20/4/2026 | 17/6/2026 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | |
| Aplazada | Media (4.7) | 0.27% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sourcecodester Vehicle Parking Area Management SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment SchedulerAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php. | |
| Aplazada | Baja (2.7) | 0.39% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php. |