Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.37% | — | Nikhil-bhalerao Simple Library Management System | 17/7/2024 | 17/6/2026 | A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries. | |
| Analizada | Crítica (9.8) | 0.65% | — | Oretnom23 Simple Library Management System | 16/7/2024 | 17/6/2026 | Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php. | |
| Aplazada | Alta (8.1) | 0.36% | — | Koha Library Management SystemAI | 19/3/2024 | 17/6/2026 | A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users… | |
| Analizada | Crítica (9.8) | 0.96% | — | Fabian Library Management System | 29/2/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Library Management System 2.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument student leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Crítica (9.8) | 0.97% | — | Fabian Library Management System | 29/2/2024 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (4.9) | 0.55% | — | Slims Senayan Library Management System | 21/2/2024 | 17/6/2026 | SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. | |
| Modificada | Crítica (9.8) | 0.65% | — | Fabian Library Management System | 26/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. Affected is an unknown function of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.75% | — | Slims Senayan Library Management System Bulian | 1/12/2023 | 17/6/2026 | SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate. | |
| Modificada | Alta (8.8) | 0.75% | — | Slims Senayan Library Management System Bulian | 1/12/2023 | 17/6/2026 | Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php. | |
| Modificada | Alta (8.8) | 1.1% | — | Slims Senayan Library Management SystemSlims Senayan Library Management System Bulian | 31/10/2023 | 17/6/2026 | SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php. | |
| Modificada | Alta (8.8) | 0.56% | — | Slims Senayan Library Management System | 2/10/2023 | 17/6/2026 | Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter. | |
| Modificada | Alta (8.8) | 0.74% | — | Slims Senayan Library Management System | 1/9/2023 | 17/6/2026 | Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | |
| Modificada | Media (6.1) | 0.39% | — | Slims Senayan Library Management System | 1/9/2023 | 17/6/2026 | Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php. | |
| Modificada | Alta (7.5) | 0.75% | — | Slims Senayan Library Management System | 14/4/2023 | 17/6/2026 | SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information. | |
| Modificada | Alta (7.5) | 0.79% | — | Slims Senayan Library Management System | 5/12/2022 | 17/6/2026 | SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. | |
| Modificada | Alta (7.2) | 0.75% | — | Slims Senayan Library Management System | 1/11/2022 | 17/6/2026 | Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php. | |
| Modificada | Media (4.8) | 0.41% | — | Slims Senayan Library Management System | 1/11/2022 | 17/6/2026 | Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Slims Senayan Library Management System | 12/9/2022 | 17/6/2026 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php. | |
| Modificada | Media (6.1) | 0.50% | — | Slims Senayan Library Management System | 12/9/2022 | 17/6/2026 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar. | |
| Modificada | Crítica (9.8) | 1.0% | — | Library Management System Project Library Management System | 12/9/2022 | 17/6/2026 | In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection. | |
| Modificada | Crítica (9.8) | 0.91% | — | Library Management System Project Library Management System | 30/8/2022 | 17/6/2026 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php. | |
| Modificada | Crítica (9.8) | 0.91% | — | Library Management System Project Library Management System | 30/8/2022 | 17/6/2026 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php. | |
| Modificada | Crítica (9.8) | 0.91% | — | Library Management System Project Library Management System | 30/8/2022 | 17/6/2026 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php. | |
| Modificada | Crítica (9.8) | 0.91% | — | Library Management System Project Library Management System | 30/8/2022 | 17/6/2026 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php. | |
| Modificada | Crítica (9.8) | 0.91% | — | Library Management System Project Library Management System | 30/8/2022 | 17/6/2026 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php. |