Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

255 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.6)0.42%—Schule111 Schule School Management System23/5/202517/6/2026
Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be exploited to send…
AnalizadaMedia (6.6)0.38%—Schule111 Schule School Management System22/5/202517/6/2026
Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the value of data.role is trustworthy on the…
AnalizadaMedia (6.6)0.27%—Schule111 Schule School Management System22/5/202517/6/2026
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only 9000 possible combinations. This small…
AnalizadaAlta (8.8)0.37%—Dasinfomedia School Management System7/3/202517/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email and password through the…
AnalizadaMedia (5.3)0.33%—Dasinfomedia School Management System7/3/202517/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaMedia (5.3)0.31%—Dasinfomedia School Management System7/3/202517/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it possible for unauthenticated attackers…
AnalizadaMedia (6.5)0.39%—Dasinfomedia School Management System7/3/202517/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the…
AnalizadaMedia (6.5)0.35%—Dasinfomedia School Management System7/3/202517/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AnalizadaAlta (8.8)1.1%—Dasinfomedia School Management System23/11/202417/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.8)1.7%—Dasinfomedia School Management System23/11/202417/6/2026
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on…
AnalizadaAlta (7.2)0.38%—Lopalopa Responsive School Management System28/8/202417/6/2026
A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page
AnalizadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
AnalizadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
ModificadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
ModificadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
AnalizadaCrítica (9.8)0.59%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
AnalizadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
AnalizadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
ModificadaCrítica (9.8)0.60%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
AnalizadaCrítica (9.8)0.59%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
AnalizadaCrítica (9.8)0.58%—Arajajyothibabu School Management System20/8/202417/6/2026
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
AnalizadaMedia (5.3)0.45%—Oretnom23 CAR Driving School Management System12/8/202417/6/2026
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_package. The manipulation of the argument name/description/training_duration leads to cross site scripting.…
AnalizadaMedia (5.3)0.45%—Oretnom23 CAR Driving School Management System12/8/202417/6/2026
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site…
AnalizadaMedia (5.3)0.45%—Oretnom23 CAR Driving School Management System12/8/202417/6/2026
A vulnerability was found in Sourcecodester Car Driving School Management System 1.0. It has been classified as critical. Affected is the function save_package of the file /classes/Master.php?f=save_package. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaMedia (5.3)0.45%—Oretnom23 CAR Driving School Management System12/8/202417/6/2026
A vulnerability was found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This issue affects the function delete_enrollment of the file Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
Orbitaley — Vulnerabilidades