Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php. | |
| Aplazada | Baja (2.7) | 0.32% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Storage Unit Rental Management SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 13/4/2026 | 17/6/2026 | A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Construction Management SystemAI | 13/4/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /employees.php. Performing a manipulation of the argument Name results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 13/4/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 13/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 13/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may… | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/admin/repairs/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/repairs/manage_repair.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php. | |
| Analizada | Alta (7.1) | 0.16% | — | Montala Resourcespace | 12/4/2026 | 17/6/2026 | ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords parameter in collection_edit.php. Attackers can submit POST requests with crafted SQL payloads in the keywords field to extract sensitive… | |
| Analizada | Crítica (9.8) | 0.50% | — | Itsourcecode Online Student Enrollment System | 10/4/2026 | 17/6/2026 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. |