Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

1390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.36%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP29/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated…
ModificadaMedia (6.1)0.36%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP29/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnerability affects unknown code of the file Master.php?a=save_earning. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The identifier of this…
ModificadaMedia (6.1)0.36%—Oretnom23 Earnings AND Expense Tracker Application29/3/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated…
ModificadaCrítica (9.8)0.79%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/username/password leads to improper authentication. It is possible to initiate the…
ModificadaMedia (6.1)0.39%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Medicine Tracker System 1.0. Affected by this issue is some unknown functionality of the file app/?page=medicines/manage_medicine. The manipulation of the argument name/description with the input <script>alert('2')</script> leads to…
ModificadaCrítica (9.8)0.81%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracker System 1.0. This issue affects some unknown processing of the file medicines/view_details.php of the component GET Parameter Handler. The manipulation of the argument GET leads to sql injection. The attack may be…
ModificadaCrítica (9.8)0.74%—Online Graduate Tracer System Project Online Graduate Tracer System14/3/202317/6/2026
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been classified as critical. This affects the function mysqli_query of the file bsitemp.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)0.74%—Online Graduate Tracer System Project Online Graduate Tracer System10/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file admin/prof.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.74%—Online Graduate Tracer System Project Online Graduate Tracer System10/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Online Graduate Tracer System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/search_it.php. The manipulation of the argument input leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.74%—Online Graduate Tracer System Project Online Graduate Tracer System10/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file admin/adminlog.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.60%—File Tracker Manager System Project File Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester File Tracker Manager System 1.0. This affects an unknown part of the file normal/borrow1.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to initiate…
ModificadaCrítica (9.8)0.82%—File Tracker Manager System Project File Tracker Management System9/3/202317/6/2026
A vulnerability was found in SourceCodester File Tracker Manager System 1.0. It has been classified as critical. Affected is an unknown function of the file /file_manager/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to launch the…
ModificadaAlta (8.1)0.57%—Online Graduate Tracer System Project Online Graduate Tracer System9/3/202317/6/2026
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects the function mysqli_query of the file admin_cs.php. The manipulation leads to sql injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is…
ModificadaCrítica (9.8)0.76%—Sales Tracker Management System Project Sales Tracker Management System9/3/202317/6/2026
A vulnerability has been found in SourceCodester Sales Tracker Management System 1.0 and classified as critical. This vulnerability affects the function delete_client of the file classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.76%—Sales Tracker Management System Project Sales Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/clients/manage_client.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.76%—Sales Tracker Management System Project Sales Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Sales Tracker Management System 1.0. Affected by this issue is some unknown functionality of the file admin/clients/view_client.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The…
ModificadaMedia (6.5)0.71%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable3/3/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by…
ModificadaCrítica (9.8)0.58%—Online Graduate Tracer System Project Online Graduate Tracer System26/2/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file tracking/admin/add_acc.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The…
ModificadaAlta (8.8)0.49%—Sales Tracker Management System Project Sales Tracker Management System24/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)0.54%—Sales Tracker Management System Project Sales Tracker Management System23/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/?page=user/manage_user of the component Edit User. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaAlta (8.1)0.49%—Sales Tracker Management System Project Sales Tracker Management System22/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. Affected is an unknown function of the file admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack…
ModificadaMedia (5.4)0.54%—Go-redrock Tutortrac21/2/202317/6/2026
Múltiples vulnerabilidades de cross-site scripting (XSS) almacenadas en Redrock Software TutorTrac anterior a v4.2.170210 permiten a los atacantes ejecutar scripts web arbitrarias o HTML a través de un payload manipulado inyectado en los campos de motivo y ubicación de la página de listado de visitas.
ModificadaMedia (5.3)0.61%—Schismtracker Schism Tracker17/2/202317/6/2026
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c.
ModificadaAlta (7.8)0.17%—Intel Trace Analyzer AND Collector16/2/202317/6/2026
Out-of-bounds read in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.18%—Intel Trace Analyzer AND Collector16/2/202317/6/2026
Integer overflow in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access.