Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 329 respecto a la semana anterior
Críticas / altas1265▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2)0.29%—Itsourcecode Leave Management System8/10/20258/10/2026
Se ha descubierto una vulnerabilidad de seguridad en itsourcecode Leave Management System 1.0. Esto afecta a la función redirect del archivo /module/employee/controller.PHP?action=reset del componente Query Parameter Gestor. Realizar una manipulación del argumento ID resulta en cross-site scripting. Es posible iniciar…
AnalizadaMedia (5.5)0.48%—Itsourcecode Leave Management System8/10/20258/10/2026
Una vulnerabilidad fue identificada en itsourcecode Leave Management System 1.0. Esto afecta una función desconocida del archivo /reset.PHP. Tal manipulación del argumento employid lleva a inyección SQL. El ataque puede ser realizado desde remoto. El exploit está disponible públicamente y podría ser usado.
AnalizadaAlta (7.8)0.12%—IBM Infosphere Data Replication Vsam FOR Z/os Remote Source7/10/202517/6/2026
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
AplazadaMedia (5.1)0.36%—Bbmri-eric Biobanking AND Biomolecular Resources NegotiatorAI7/10/202517/6/2026
Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infrastructure (BBMRI-ERIC), consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using parameter text in '/api/v3/negotiations/<postUID>/posts'. This…
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Open Source JOB Portal28/9/202517/6/2026
A security flaw has been discovered in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/company/index.php?view=edit. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the…
AnalizadaBaja (2.1)0.34%—Angeljudesuarez Open Source JOB Portal28/9/202517/6/2026
A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected is an unknown function of the file /admin/employee/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
AnalizadaBaja (2.1)0.35%—Angeljudesuarez Open Source JOB Portal28/9/202517/6/2026
A weakness has been identified in itsourcecode Open Source Job Portal 1.0. Impacted is an unknown function of the file /admin/vacancy/index.php?view=edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and…
AnalizadaBaja (2.1)0.33%—Angeljudesuarez Open Source JOB Portal27/9/202517/6/2026
A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation of the argument photo leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit…
AnalizadaBaja (2.1)0.38%—Angeljudesuarez Open Source JOB Portal27/9/202517/6/2026
A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/category/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly…
AnalizadaBaja (2.1)0.34%—Angeljudesuarez Open Source JOB Portal26/9/202530/9/2026
Se ha encontrado una vulnerabilidad en itsourcecode Open Source Job Portal 1.0. Se ve afectada por este problema alguna funcionalidad desconocida del archivo /admin/user/index.php?view=edit. La manipulación del argumento ID conduce a una inyección SQL. El ataque puede realizarse de forma remota. El exploit ha sido…
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Open Source JOB Portal23/9/202517/6/2026
A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. This affects an unknown function of the file /jobportal/admin/login.php. Such manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AplazadaMedia (4.3)0.28%—Meitar Subresource Integrity SRI ManagerAI22/9/202517/6/2026
Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0.
AnalizadaMedia (5.5)0.59%—Itsourcecode Student Information Management System18/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed…
AnalizadaMedia (5.5)0.48%—Itsourcecode Web-based Internet Laboratory Management System17/9/202525/9/2026
Una falla de seguridad ha sido descubierta en itsourcecode Web-Based Internet Laboratory Management System 1.0. La función afectada es User::AuthenticateUser del archivo login.PHP. La manipulación del argumento user_email conduce a una inyección SQL. La explotación remota del ataque es posible. El exploit ha sido…
AnalizadaBaja (2.1)0.39%—Itsourcecode Online Public Access Catalog17/9/202525/9/2026
Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Public Access Catalog OPAC 1.0. Esto afecta a una función desconocida del archivo mysearch.php del componente POST Parameter Handler. Dicha manipulación del argumento search_field/search_text conduce a inyección SQL. El ataque puede ser realizado…
ModificadaMedia (5.4)0.21%—Fabian Human Resource Integrated System16/9/20255/7/2026
code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field.
AnalizadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management System14/9/202517/6/2026
A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Itsourcecode Baptism Information Management System14/9/202530/9/2026
Se determinó una vulnerabilidad en itsourcecode Baptism Information Management System 1.0. Afectada es una función desconocida del archivo /listbaptism.PHP. Esta manipulación del argumento bapt_id causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser…
ModificadaBaja (2)0.70%💥 ExploitSourcefabric Rpi-jukebox-rfid13/9/202517/6/2026
A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and…
AnalizadaBaja (2)0.31%—Sourcefabric Rpi-jukebox-rfid13/9/202517/6/2026
A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Executing manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was…
AnalizadaBaja (2)0.30%—Sourcefabric Rpi-jukebox-rfid13/9/202517/6/2026
A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFilesFolders.php. Performing manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be…
AnalizadaBaja (2)0.30%—Sourcefabric Rpi-jukebox-rfid13/9/202517/6/2026
A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/cardEdit.php. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaBaja (2)0.29%—Sourcefabric Rpi-jukebox-rfid13/9/202517/6/2026
A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.setWlanIpMail.php. This manipulation of the argument Email address causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was…
AnalizadaBaja (2.1)9.4%—Sourcefabric Rpi-jukebox-rfid12/9/202517/6/2026
A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/api/playlist/playsinglefile.php. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit has been…
ModificadaBaja (2.1)10%💥 ExploitSourcefabric Rpi-jukebox-rfid12/9/202517/6/2026
A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulation of the argument playlist can lead to os command injection. The attack can be launched remotely. The exploit has been…