Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
–

3005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.33%—Fabian Online Hotel Reservation System7/10/202517/6/2026
A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/editpicexec.php. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to…
ModificadaMedia (5.5)0.42%—Campcodes Online Apartment Visitor Management System7/10/202517/6/2026
A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. The affected element is an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate results in sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.5)0.42%—Campcodes Online Apartment Visitor Management System7/10/202517/6/2026
A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
ModificadaMedia (5.5)0.42%—Campcodes Online Apartment Visitor Management System7/10/202517/6/2026
A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and…
AnalizadaBaja (2)0.41%—Fabian Online Course Registration Site6/10/202517/6/2026
A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument coursecode can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and…
ModificadaMedia (5.5)0.42%—Campcodes Online Apartment Visitor Management System6/10/202517/6/2026
A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-detail.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be…
AplazadaBaja (1.9)0.27%—Langleyfcu Online Banking SystemAI6/10/202517/6/2026
A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This impacts an unknown function of the file /customer_add_action.php of the component Add Customer Page. The manipulation of the argument First Name leads to cross site scripting. Remote exploitation of…
AnalizadaMedia (5.5)0.42%—Fabian Online Course Registration Site6/10/202517/6/2026
A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AnalizadaMedia (6.5)0.26%—Phpgurukul Online Shopping Portal Project2/10/202517/6/2026
PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.
AplazadaCrítica (9.3)1.2%—Telenium Online WEB ApplicationAI30/9/202517/6/2026
La aplicación web Telenium Online es vulnerable debido a un endpoint PHP accesible para usuarios de red no autenticados que maneja incorrectamente la entrada proporcionada por el usuario. Esta vulnerabilidad ocurre debido a la terminación insegura de una verificación de expresión regular dentro del endpoint. Debido a…
AplazadaBaja (2.1)0.35%—Langleyfcu Online Banking SystemAI29/9/202517/6/2026
A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of the component Error Message Handler. Performing manipulation of the argument Error results in cross site…
AnalizadaBaja (2.1)0.38%—Codeastro Online Leave Application28/9/202517/6/2026
A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicationForm.php. Executing manipulation of the argument absence[] can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be…
AnalizadaBaja (2.1)0.38%—Codeastro Online Leave Application28/9/202517/6/2026
A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Other parameters might be affected as…
AnalizadaMedia (5.5)0.48%—Campcodes Advanced Online Voting System28/9/202517/6/2026
A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/candidates_edit.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System28/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/school_year.php. The manipulation of the argument school_year results in sql injection. It is possible to launch the attack remotely. The exploit has been released to…
AnalizadaBaja (2)0.38%—Projectworlds Online Tours AND Travels28/9/202517/6/2026
A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System28/9/202517/6/2026
A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/edit_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and…
AnalizadaMedia (5.5)0.42%💥 PoCCampcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument department results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.48%—Projectworlds Online Shopping System27/9/202517/6/2026
A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.48%—Fabian Online Bidding System27/9/202517/6/2026
A flaw has been found in code-projects Online Bidding System 1.0. This impacts an unknown function of the file /administrator/bidlist.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Impacted is an unknown function of the file /admin/teachers.php. The manipulation of the argument department results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /admin/edit_department.php. The manipulation of the argument d leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was determined in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/save_student.php. Executing manipulation of the argument class_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and…