Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

67 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.27%💥 PoCVishalmathur Cloudclassroom31/7/202517/6/2026
CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser, potentially leading to session hijacking…
AnalizadaMedia (6.5)0.24%💥 PoCVishalmathur Cloudclassroom31/7/202517/6/2026
A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.
ModificadaMedia (6.5)0.30%💥 PoCVishalmathur Cloudclassroom-php Project25/7/20255/7/2026
CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.
AnalizadaCrítica (9.8)0.59%—Vishalmathur Cloudclassroom-php Project20/6/202517/6/2026
A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries.
AnalizadaCrítica (9.8)0.57%💥 PoCVishalmathur Cloudclassroom-php Project18/6/202517/6/2026
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network…
AnalizadaCrítica (9.8)0.63%💥 PoCVishalmathur Cloudclassroom-php Project18/6/202517/6/2026
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and…
AnalizadaMedia (6.1)0.39%💥 PoCVishalmathur Cloudclassroom-php Project9/6/202517/6/2026
Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.
AnalizadaAlta (7.3)1.1%💥 ExploitVishalmathur Cloudclassroom-php Project2/6/202517/6/2026
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.
AnalizadaAlta (7.3)0.24%—Vishalmathur Cloudclassroom-php Project2/6/202517/6/2026
A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.
AnalizadaMedia (6.1)0.49%—Vishalmathur Cloudclassroom-php Project26/2/202517/6/2026
A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.
AnalizadaMedia (5.1)0.47%—Classroombookings10/10/202417/6/2026
A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. Upgrading to…
AnalizadaMedia (5.3)0.46%—Classroombookings10/10/202417/6/2026
A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Page. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The…
ModificadaMedia (6.1)0.41%—Braincert Virtual Classroom API14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BrainCert BrainCert – HTML5 Virtual Classroom allows Reflected XSS.This issue affects BrainCert – HTML5 Virtual Classroom: from n/a through 1.30.
ModificadaCrítica (9.8)0.60%—Braincert Virtual Classroom7/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
ModificadaMedia (6.1)0.46%—Classroombookings20/1/202317/6/2026
Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php.
ModificadaCrítica (9.8)0.66%—Classroom-engagement-system Project Classroom-engagement-system12/1/202316/6/2026
A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is 096de5815c7b414e7339f3439522a446098fb73a. It is recommended to…
ModificadaAlta (7.2)1.0%—Classroombookings14/12/202017/6/2026
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
Orbitaley — Vulnerabilidades