Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

5381 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.39%—Fabian Refugee Food Management System29/12/20257/10/2026
Se ha descubierto una vulnerabilidad de seguridad en el sistema de gestión de alimentos para refugiados 1.0 de code-projects. El elemento afectado es una función desconocida del archivo /home/pagenateRefugeesList.PHP. La manipulación del argumento rfid resulta en inyección SQL. La explotación remota del ataque es…
AnalizadaMedia (5.5)0.38%—Angeljudesuarez Student Management System29/12/20257/10/2026
Se identificó una vulnerabilidad en itsourcecode Student Management System 1.0. Afecta a una función desconocida del archivo /statistical.php. Dicha manipulación del argumento ID conduce a una inyección SQL. El ataque puede ejecutarse de forma remota. El exploit está disponible públicamente y podría ser utilizado.
AnalizadaMedia (6.5)0.28%💥 PoCKrishanmurariji Student Management System26/12/202517/6/2026
SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an…
AnalizadaMedia (5.5)0.38%—Angeljudesuarez Student Management System25/12/20257/10/2026
Se detectó una vulnerabilidad en itsourcecode Student Management System 1.0. El elemento afectado es una función desconocida del archivo /list_report.php. La manipulación del argumento sy resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit es ahora público y puede ser usado.
AnalizadaMedia (5.5)0.38%—Angeljudesuarez Student Management System25/12/20257/10/2026
Se ha detectado una vulnerabilidad de seguridad en itsourcecode Student Management System 1.0. El elemento afectado es una función desconocida del archivo /form137.php. La manipulación del argumento ID conduce a inyección SQL. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado públicamente y puede…
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Student Management System25/12/20257/10/2026
Se ha descubierto una falla de seguridad en itsourcecode Student Management System 1.0. Este problema afecta a algún procesamiento desconocido del archivo /student_p.PHP. La manipulación del argumento ID resulta en inyección SQL. El ataque puede iniciarse de forma remota. El exploit ha sido liberado al público y puede…
AnalizadaBaja (2.1)0.34%—Fabian Student File Management System24/12/202517/6/2026
A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.php. Such manipulation of the argument File leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
AnalizadaMedia (5.5)0.39%—Angeljudesuarez Student Management System23/12/202517/6/2026
A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the file /record.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
AnalizadaMedia (5.5)0.38%—Fabian Refugee Food Management System22/12/202525/9/2026
Se determinó una vulnerabilidad en code-projects Refugee Food Management System 1.0. El elemento afectado es una función desconocida del archivo /home/home.php. Esta manipulación del argumento a causa inyección SQL. El ataque puede llevarse a cabo de forma remota. El exploit ha sido divulgado públicamente y puede ser…
ModificadaBaja (1.9)0.24%—Campcodes Complete Online Beauty Parlor Management System21/12/202517/6/2026
A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/bwdates-reports-details.php. Executing a manipulation of the argument fromdate can lead to cross site scripting. The attack may be launched remotely. The…
ModificadaMedia (5.5)0.38%—Campcodes Complete Online Beauty Parlor Management System21/12/202517/6/2026
A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing a manipulation of the argument viewid results in sql injection. The attack may be initiated remotely. The exploit has been released…
AnalizadaMedia (5.5)0.38%—Campcodes Complete Online Beauty Parlor Management System21/12/202517/6/2026
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.39%—Angeljudesuarez Student Management System19/12/202517/6/2026
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /candidates_report.php. The manipulation of the argument school_year leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and…
AnalizadaMedia (5.5)0.38%—Fabian Simple Blood Donor Management System19/12/202517/6/2026
A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unknown function of the file /editedcampaign.php. The manipulation of the argument campaignname results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
AnalizadaMedia (5.5)0.38%—Fabian Simple Blood Donor Management System19/12/202517/6/2026
A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unknown function of the file /editeddonor.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and…
ModificadaMedia (5.5)0.44%—Campcodes Supplier Management System19/12/202517/6/2026
A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be…
AnalizadaBaja (2)0.40%—Codeastro Real Estate Management System19/12/202517/6/2026
A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component Administrator Endpoint. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaBaja (2)0.36%—Codeastro Real Estate Management System19/12/202517/6/2026
A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and…
ModificadaBaja (2)0.36%—Codeastro Real Estate Management System19/12/202517/6/2026
A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the…
AnalizadaBaja (2)0.36%—Codeastro Real Estate Management System19/12/202517/6/2026
A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and…
AnalizadaMedia (6.1)0.26%—Yohanawi Hotel Management System18/12/202517/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.
ModificadaBaja (2.1)0.29%—Campcodes Advanced Voting Management System18/12/202517/6/2026
A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried…
AnalizadaBaja (2.1)0.35%—Lerouxyxchire Client Database Management System18/12/202517/6/2026
A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.39%—Campcodes Supplier Management System18/12/202517/6/2026
A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The manipulation of the argument cmbAreaCode leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
AnalizadaBaja (1.9)0.28%—Xiweicheng Teamwork Management System17/12/202517/6/2026
A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be…