Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
1390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.36% | — | Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP | 29/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated… | |
| Modificada | Media (6.1) | 0.36% | — | Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP | 29/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnerability affects unknown code of the file Master.php?a=save_earning. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The identifier of this… | |
| Modificada | Media (6.1) | 0.36% | — | Oretnom23 Earnings AND Expense Tracker Application | 29/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated… | |
| Modificada | Crítica (9.8) | 0.79% | — | Medicine Tracker System Project Medicine Tracker System | 17/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/username/password leads to improper authentication. It is possible to initiate the… | |
| Modificada | Media (6.1) | 0.39% | — | Medicine Tracker System Project Medicine Tracker System | 17/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Medicine Tracker System 1.0. Affected by this issue is some unknown functionality of the file app/?page=medicines/manage_medicine. The manipulation of the argument name/description with the input <script>alert('2')</script> leads to… | |
| Modificada | Crítica (9.8) | 0.81% | — | Medicine Tracker System Project Medicine Tracker System | 17/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracker System 1.0. This issue affects some unknown processing of the file medicines/view_details.php of the component GET Parameter Handler. The manipulation of the argument GET leads to sql injection. The attack may be… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 14/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 10/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file admin/prof.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 10/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Graduate Tracer System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/search_it.php. The manipulation of the argument input leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 10/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file admin/adminlog.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.60% | — | File Tracker Manager System Project File Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester File Tracker Manager System 1.0. This affects an unknown part of the file normal/borrow1.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to initiate… | |
| Modificada | Crítica (9.8) | 0.82% | — | File Tracker Manager System Project File Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester File Tracker Manager System 1.0. It has been classified as critical. Affected is an unknown function of the file /file_manager/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to launch the… | |
| Modificada | Alta (8.1) | 0.57% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 9/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects the function mysqli_query of the file admin_cs.php. The manipulation leads to sql injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is… | |
| Modificada | Crítica (9.8) | 0.76% | — | Sales Tracker Management System Project Sales Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Sales Tracker Management System 1.0 and classified as critical. This vulnerability affects the function delete_client of the file classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Sales Tracker Management System Project Sales Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/clients/manage_client.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Sales Tracker Management System Project Sales Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Sales Tracker Management System 1.0. Affected by this issue is some unknown functionality of the file admin/clients/view_client.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The… | |
| Modificada | Media (6.5) | 0.71% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 3/3/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by… | |
| Modificada | Crítica (9.8) | 0.58% | — | Online Graduate Tracer System Project Online Graduate Tracer System | 26/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file tracking/admin/add_acc.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The… | |
| Modificada | Alta (8.8) | 0.49% | — | Sales Tracker Management System Project Sales Tracker Management System | 24/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.54% | — | Sales Tracker Management System Project Sales Tracker Management System | 23/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/?page=user/manage_user of the component Edit User. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Alta (8.1) | 0.49% | — | Sales Tracker Management System Project Sales Tracker Management System | 22/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. Affected is an unknown function of the file admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack… | |
| Modificada | Media (5.4) | 0.54% | — | Go-redrock Tutortrac | 21/2/2023 | 17/6/2026 | Múltiples vulnerabilidades de cross-site scripting (XSS) almacenadas en Redrock Software TutorTrac anterior a v4.2.170210 permiten a los atacantes ejecutar scripts web arbitrarias o HTML a través de un payload manipulado inyectado en los campos de motivo y ubicación de la página de listado de visitas. | |
| Modificada | Media (5.3) | 0.61% | — | Schismtracker Schism Tracker | 17/2/2023 | 17/6/2026 | An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Trace Analyzer AND Collector | 16/2/2023 | 17/6/2026 | Out-of-bounds read in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Trace Analyzer AND Collector | 16/2/2023 | 17/6/2026 | Integer overflow in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access. |