Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.23% | — | Mojoomla School ManagementAI | 26/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through 93.2.0. | |
| Analizada | Baja (2) | 0.28% | — | Donbermoy Advanced School Management System | 21/8/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/notice/addNotice. The manipulation of the argument noticeSubject results in cross site scripting. It is possible to launch the attack remotely. The exploit is now… | |
| Aplazada | Alta (8.8) | 0.59% | — | School Management SystemAI | 16/8/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the homework.php file in all versions up to, and including, 93.2.0. This makes it possible for authenticated attackers, with Student-level access and above, to upload arbitrary… | |
| Aplazada | Alta (7.5) | 0.43% | — | School Management SystemAI | 16/8/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters across multiple AJAX action in all versions up to, and including, 93.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Modificada | Alta (8.2) | 0.42% | — | Getprojects Create School Management System | 30/7/2025 | 17/6/2026 | GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php. | |
| Aplazada | Alta (8.8) | 0.72% | — | School Management SystemAI | 18/7/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Mojoomla School ManagementAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Mojoomla School ManagementAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows Blind SQL Injection. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (7.5) | 0.72% | — | Mojoomla School ManagementAIPHPAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla School Management allows PHP Local File Inclusion. This issue affects School Management: from n/a through 93.0.0. | |
| Analizada | Media (6.6) | 0.42% | — | Schule111 Schule School Management System | 23/5/2025 | 17/6/2026 | Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be exploited to send… | |
| Aplazada | Alta (7.1) | 0.28% | — | Mojoomla School ManagementAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (8.5) | 0.33% | — | Mojoomla School ManagementAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0. | |
| Analizada | Media (6.6) | 0.38% | — | Schule111 Schule School Management System | 22/5/2025 | 17/6/2026 | Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the value of data.role is trustworthy on the… | |
| Analizada | Media (6.6) | 0.27% | — | Schule111 Schule School Management System | 22/5/2025 | 17/6/2026 | Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only 9000 possible combinations. This small… | |
| Analizada | Alta (8.8) | 0.37% | — | Dasinfomedia School Management System | 7/3/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email and password through the… | |
| Analizada | Media (5.3) | 0.33% | — | Dasinfomedia School Management System | 7/3/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.3) | 0.31% | — | Dasinfomedia School Management System | 7/3/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (6.5) | 0.39% | — | Dasinfomedia School Management System | 7/3/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the… | |
| Analizada | Media (6.5) | 0.35% | — | Dasinfomedia School Management System | 7/3/2025 | 17/6/2026 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Media (5.1) | 0.37% | — | Campcodes School Management Software | 10/2/2025 | 17/6/2026 | A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academic-calendar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.45% | — | Campcodes School Management Software | 30/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.3) | 0.38% | — | Itechscripts School Management SoftwareAI | 26/1/2025 | 17/6/2026 | A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the file /notice-edit.php. The manipulation of the argument aid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.38% | — | Campcodes School Management Software | 24/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The manipulation of the argument Notice leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Baja (2.3) | 0.49% | — | Campcodes School Management Software | 22/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads to improper control of resource identifiers. It is possible to initiate the attack remotely. The complexity of an attack… | |
| Analizada | Media (5.3) | 0.47% | — | Campcodes School Management Software | 20/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. This affects an unknown part of the file /chat/group/send of the component Chat History. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The… |