Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

3978 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2)0.38%—Projectworlds Online Tours AND Travels28/9/202517/6/2026
A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System28/9/202517/6/2026
A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/edit_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and…
AnalizadaMedia (5.5)0.42%💥 PoCCampcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument department results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.48%—Projectworlds Online Shopping System27/9/202517/6/2026
A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.48%—Fabian Online Bidding System27/9/202517/6/2026
A flaw has been found in code-projects Online Bidding System 1.0. This impacts an unknown function of the file /administrator/bidlist.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Impacted is an unknown function of the file /admin/teachers.php. The manipulation of the argument department results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /admin/edit_department.php. The manipulation of the argument d leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202517/6/2026
A vulnerability was determined in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/save_student.php. Executing manipulation of the argument class_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and…
AnalizadaMedia (5.5)0.48%—Campcodes Online Learning Management System27/9/202530/9/2026
Una vulnerabilidad fue encontrada en Campcodes Online Learning Management System 1.0. Esto afecta una parte desconocida del archivo /admin/edit_student.php. Realizar la manipulación del argumento cys resulta en inyección SQL. El ataque puede ser llevado a cabo remotamente. El exploit ha sido hecho público y podría ser…
AnalizadaMedia (5.5)0.48%—Fabian Online Hotel Reservation System27/9/202517/6/2026
A vulnerability was detected in SourceCodester Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/updateaddress.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AnalizadaBaja (2.1)0.34%—Angeljudesuarez Online Clinic Management System26/9/202517/6/2026
A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of the file /details.php?action=post. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could…
AnalizadaMedia (5.5)0.42%—Fabian Online Hotel Reservation System23/9/202517/6/2026
A flaw has been found in Reservation Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /reservation/paypalpayout.php. Executing manipulation of the argument confirm can lead to sql injection. The attack may be launched remotely. The exploit has been published…
AnalizadaMedia (5.5)0.48%—Fabian Online Bidding System23/9/202517/6/2026
A vulnerability was detected in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /administrator/wew.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
AnalizadaMedia (5.5)0.60%—Fabian Online Bidding System23/9/202517/6/2026
A security vulnerability has been detected in code-projects Online Bidding System 1.0. This impacts an unknown function of the file /administrator/weweee.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
AnalizadaBaja (2.1)0.38%—Campcodes Online Beauty Parlor Management System23/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The…
AnalizadaBaja (2.1)0.38%—Campcodes Online Beauty Parlor Management System23/9/202517/6/2026
A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. Affected is an unknown function of the file /admin/view-appointment.php. The manipulation of the argument viewid leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A weakness has been identified in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_user.php. Executing manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the…
AplazadaMedia (5.9)0.22%—Ezee Technosys Ezee Online Hotel Booking EngineAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine online-booking-engine allows Stored XSS.This issue affects eZee Online Hotel Booking Engine: from n/a through <= 1.0.0.
AplazadaMedia (5.9)0.30%—Onlineoptimisation WP Mailto LinksAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Online Optimisation WP Mailto Links wp-mailto-links allows Stored XSS.This issue affects WP Mailto Links: from n/a through <= 3.1.4.
AnalizadaMedia (5.5)0.68%—Campcodes Online Learning Management System22/9/202517/6/2026
A vulnerability was detected in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/edit_user.php. Performing manipulation of the argument firstname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may…
AnalizadaMedia (5.5)0.56%—Campcodes Online Learning Management System22/9/202517/6/2026
A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is an unknown function of the file /admin/department.php. Such manipulation of the argument d leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may…
AnalizadaBaja (2.1)0.38%—Campcodes Online Beauty Parlor Management System22/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/edit-customer-detailed.php. The manipulation of the argument editid results in sql injection. The attack may be launched remotely. The exploit has been released to…
AnalizadaBaja (2.1)0.38%—Campcodes Online Beauty Parlor Management System22/9/202517/6/2026
A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit is publicly…