Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 329 respecto a la semana anterior
Críticas / altas1265▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2) | 0.29% | — | Itsourcecode Leave Management System | 8/10/2025 | 8/10/2026 | Se ha descubierto una vulnerabilidad de seguridad en itsourcecode Leave Management System 1.0. Esto afecta a la función redirect del archivo /module/employee/controller.PHP?action=reset del componente Query Parameter Gestor. Realizar una manipulación del argumento ID resulta en cross-site scripting. Es posible iniciar… | |
| Analizada | Media (5.5) | 0.48% | — | Itsourcecode Leave Management System | 8/10/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en itsourcecode Leave Management System 1.0. Esto afecta una función desconocida del archivo /reset.PHP. Tal manipulación del argumento employid lleva a inyección SQL. El ataque puede ser realizado desde remoto. El exploit está disponible públicamente y podría ser usado. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM Infosphere Data Replication Vsam FOR Z/os Remote Source | 7/10/2025 | 17/6/2026 | IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system. | |
| Aplazada | Media (5.1) | 0.36% | — | Bbmri-eric Biobanking AND Biomolecular Resources NegotiatorAI | 7/10/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infrastructure (BBMRI-ERIC), consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using parameter text in '/api/v3/negotiations/<postUID>/posts'. This… | |
| Analizada | Media (5.5) | 0.42% | — | Angeljudesuarez Open Source JOB Portal | 28/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/company/index.php?view=edit. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the… | |
| Analizada | Baja (2.1) | 0.34% | — | Angeljudesuarez Open Source JOB Portal | 28/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected is an unknown function of the file /admin/employee/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.35% | — | Angeljudesuarez Open Source JOB Portal | 28/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Open Source Job Portal 1.0. Impacted is an unknown function of the file /admin/vacancy/index.php?view=edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and… | |
| Analizada | Baja (2.1) | 0.33% | — | Angeljudesuarez Open Source JOB Portal | 27/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation of the argument photo leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Baja (2.1) | 0.38% | — | Angeljudesuarez Open Source JOB Portal | 27/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/category/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly… | |
| Analizada | Baja (2.1) | 0.34% | — | Angeljudesuarez Open Source JOB Portal | 26/9/2025 | 30/9/2026 | Se ha encontrado una vulnerabilidad en itsourcecode Open Source Job Portal 1.0. Se ve afectada por este problema alguna funcionalidad desconocida del archivo /admin/user/index.php?view=edit. La manipulación del argumento ID conduce a una inyección SQL. El ataque puede realizarse de forma remota. El exploit ha sido… | |
| Analizada | Media (5.5) | 0.42% | — | Angeljudesuarez Open Source JOB Portal | 23/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. This affects an unknown function of the file /jobportal/admin/login.php. Such manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (4.3) | 0.28% | — | Meitar Subresource Integrity SRI ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0. | |
| Analizada | Media (5.5) | 0.59% | — | Itsourcecode Student Information Management System | 18/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed… | |
| Analizada | Media (5.5) | 0.48% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/9/2025 | 25/9/2026 | Una falla de seguridad ha sido descubierta en itsourcecode Web-Based Internet Laboratory Management System 1.0. La función afectada es User::AuthenticateUser del archivo login.PHP. La manipulación del argumento user_email conduce a una inyección SQL. La explotación remota del ataque es posible. El exploit ha sido… | |
| Analizada | Baja (2.1) | 0.39% | — | Itsourcecode Online Public Access Catalog | 17/9/2025 | 25/9/2026 | Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Public Access Catalog OPAC 1.0. Esto afecta a una función desconocida del archivo mysearch.php del componente POST Parameter Handler. Dicha manipulación del argumento search_field/search_text conduce a inyección SQL. El ataque puede ser realizado… | |
| Modificada | Media (5.4) | 0.21% | — | Fabian Human Resource Integrated System | 16/9/2025 | 5/7/2026 | code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field. | |
| Analizada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 30/9/2026 | Se determinó una vulnerabilidad en itsourcecode Baptism Information Management System 1.0. Afectada es una función desconocida del archivo /listbaptism.PHP. Esta manipulación del argumento bapt_id causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser… | |
| Modificada | Baja (2) | 0.70% | 💥 Exploit | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and… | |
| Analizada | Baja (2) | 0.31% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Executing manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFilesFolders.php. Performing manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/cardEdit.php. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Baja (2) | 0.29% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.setWlanIpMail.php. This manipulation of the argument Email address causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 9.4% | — | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/api/playlist/playsinglefile.php. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Baja (2.1) | 10% | 💥 Exploit | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulation of the argument playlist can lead to os command injection. The attack can be launched remotely. The exploit has been… |