Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
22.727 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Kishor-23 Food Waste Management SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file login.php of the component Login Flow. Such manipulation of the argument PHPSESSID leads to session fixiation. The… | |
| Aplazada | Media (5.5) | 0.26% | — | Kishor-23 Food Waste Management SystemAI | 5/10/2026 | 6/10/2026 | A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file delivery/deliverysignup.php of the component Registration Page. This manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.26% | — | Kishor-23 Food Waste Management SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is an unknown function of the file admin/signup.php of the component Admin Registration. The manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.26% | — | Kishor-23 Food Waste Management SystemAI | 5/10/2026 | 6/10/2026 | A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql… | |
| Aplazada | Media (5.5) | 0.26% | — | Kishor-23 Food Waste Management SystemAI | 5/10/2026 | 6/10/2026 | A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument… | |
| Aplazada | Baja (2) | 0.20% | — | Code-projects Human Resource Management SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 5/10/2026 | 6/10/2026 | A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote.… | |
| Aplazada | Baja (2) | 0.20% | — | Code-projects Human Resource ManagementAI | 4/10/2026 | 6/10/2026 | A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched… | |
| Aplazada | Baja (2.1) | 0.22% | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 6/10/2026 | A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component Role Attribute Handler. Such manipulation of… | |
| Aplazada | Media (5.5) | 0.40% | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 6/10/2026 | A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication.… | |
| Aplazada | Media (5.5) | 0.26% | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 6/10/2026 | A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument… | |
| Aplazada | Baja (2.1) | 0.20% | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 6/10/2026 | A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Order Assignment Block. The manipulation of the argument order_id/delivery_person_id… | |
| Aplazada | Media (5.5) | 0.27% | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 6/10/2026 | A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack… | |
| Aplazada | Media (5.5) | 0.27% | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 6/10/2026 | A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice… | |
| Aplazada | Alta (8.8) | 0.37% | — | Smart ManagerAI | 3/10/2026 | 6/10/2026 | The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (5.5) | 0.43% | — | Onetwothreeneth Hospital Management SystemAI | 2/10/2026 | 2/10/2026 | A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is an unknown function of the file php/sessions.php. The manipulation of the argument ID leads to improper authentication. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.29% | — | Onetwothreeneth Hospital Management SystemAI | 2/10/2026 | 2/10/2026 | A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Loan Management SystemAI | 2/10/2026 | 6/10/2026 | A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Media (6.5) | 0.20% | — | Avez Electronics Learning Management SystemAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Student Result Management SystemAI | 2/10/2026 | 6/10/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the… | |
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. |