Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file listofstudent.php. The manipulation of the argument lname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Casap Automated Enrollment SystemAIPHPAIMysqliAI | 14/5/2024 | 17/6/2026 | SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component | |
| Modificada | Media (5.4) | 0.42% | — | Phpgurukul Pre-school Enrollment System | 15/11/2023 | 17/6/2026 | Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter. | |
| Modificada | Crítica (9.8) | 0.77% | — | Phpgurukul Pre-school Enrollment System | 15/11/2023 | 17/6/2026 | Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page. | |
| Modificada | Crítica (9.6) | 0.59% | 💥 PoC | Commscope Ruckus Cloudpath Enrollment System | 19/10/2023 | 9/7/2026 | A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity,… | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Enrollment System Project Enrollment System | 21/6/2023 | 17/6/2026 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an… | |
| Modificada | Crítica (9.8) | 14% | — | Online Student Enrollment System Project Online Student Enrollment System | 13/1/2023 | 17/6/2026 | Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php. | |
| Modificada | Media (5.4) | 0.40% | — | Online Student Enrollment System Project Online Student Enrollment System | 12/1/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /admin/register.php of Online Student Enrollment System v1.0 allows attackers to execute arbitrary web scripts via a crafted payload injected into the name parameter. | |
| Modificada | Media (6.1) | 0.66% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 8/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6) category and (7) class_name parameters in… | |
| Modificada | Media (6.1) | 0.84% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 9/7/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php. | |
| Modificada | Media (6.1) | 0.87% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php. | |
| Modificada | Media (6.1) | 0.87% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 22/7/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php. | |
| Modificada | Media (5.4) | 0.61% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 15/4/2021 | 17/6/2026 | CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter. | |
| Modificada | Crítica (9.8) | 2.2% | — | Casap Automated Enrollment System Project Casap Automated Enrollment System | 15/2/2021 | 17/6/2026 | The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Casap Automated Enrollment System Project Casap Automated Enrollment System | 9/2/2021 | 9/7/2026 | CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website. |