Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)7.1%—Sourcefabric Rpi-jukebox-rfid12/9/202517/6/2026
A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation of the argument playlist results in os command injection. The attack can be initiated remotely. The exploit has been released to the public…
AplazadaBaja (2.1)0.25%—Hjsoft HCM Human Resources Management SystemAI10/9/202517/6/2026
A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file /templates/attestation/../../selfservice/lawresource/downlawbase. Performing manipulation of the argument ID results in sql injection. Remote exploitation of…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System8/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System6/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly…
AnalizadaMedia (6.1)0.32%—Infor Global Human Resources2/9/202517/6/2026
Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code via the class parameter.
AnalizadaMedia (5.5)0.47%—Code-projects Human Resource Integrated System31/8/202517/6/2026
A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. Impacted is an unknown function of the file login_attendance2.php. Performing manipulation of the argument employee_id/date results in sql injection. The attack can be initiated remotely. The exploit has been released to the…
AnalizadaMedia (5.5)0.45%—Code-projects Human Resource Integrated System31/8/202517/6/2026
A vulnerability was identified in code-projects Human Resource Integrated System 1.0. This issue affects some unknown processing of the file /login.php. Such manipulation of the argument user/pass leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.41%—Code-projects Human Resource Integrated System31/8/202517/6/2026
A vulnerability was determined in code-projects Human Resource Integrated System 1.0. This vulnerability affects unknown code of the file /login_query12.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be…
AnalizadaMedia (5.5)0.47%—Code-projects Human Resource Integrated System31/8/202517/6/2026
A vulnerability was found in code-projects Human Resource Integrated System 1.0. This affects an unknown part of the file /log_query.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.47%—Fabian Human Resource Integrated System31/8/202517/6/2026
A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. This impacts an unknown function of the file /login_timeee.php. Performing manipulation of the argument emp_id results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may…
AplazadaAlta (8.8)0.50%—Harness Open SourceAIHarness GitnessAI29/8/202517/6/2026
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries. Prior to version 3.3.0, Open Source Harness git LFS server (Gitness) exposes api to retrieve and upload files via git LFS. Implementation of upload git LFS…
AnalizadaBaja (2.1)0.40%—Itsourcecode Student Information Management System29/8/202517/6/2026
A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and…
AnalizadaMedia (5.5)0.49%—Nelzkie15 Human Resource Information System26/8/202517/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Human Resource Information System 1.0. Este problema afecta a una funcionalidad desconocida del archivo /Superadmin_Dashboard/process/editemployee_process.php. Esta manipulación del argumento "empleado_archivo201" permite la carga sin restricciones. El ataque puede…
AnalizadaMedia (5.5)0.49%—Nelzkie15 Human Resource Information System26/8/202517/6/2026
Se ha detectado una falla en SourceCodester Human Resource Information System 1.0. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /Admin_Dashboard/process/editemployee_process.php. Esta manipulación del argumento "empleado_archivo201" provoca una carga sin restricciones. El ataque puede…
AplazadaMedia (5.3)0.31%—Provesource LTD Provesource Social ProofAI21/8/202517/6/2026
Vulnerabilidad de exposición de información confidencial del sistema a una esfera de control no autorizada en ProveSource LTD ProveSource Social Proof permite recuperar datos confidenciales integrados. Este problema afecta a ProveSource Social Proof: desde n/a hasta 3.0.5.
ModificadaMedia (6.3)0.41%—F5 Nginx PlusF5 Nginx Open Source13/8/202517/6/2026
NGINX Open Source y NGINX Plus presentan una vulnerabilidad en el módulo ngx_mail_smtp_module que podría permitir que un atacante no autenticado sobrelea la memoria del proceso de autenticación SMTP de NGINX. Como resultado, el servidor podría filtrar bytes arbitrarios enviados en una solicitud al servidor de…
AnalizadaBaja (2)0.38%—Fabian Human Resource Integrated System3/8/202517/6/2026
Se ha detectado una vulnerabilidad clasificada como problemática en code-projects Human Resource Integrated System 1.0. Afecta a una función desconocida del archivo /insert-and-view/action.php. La manipulación del contenido del argumento provoca ataques de Cross-Site Scripting. El ataque puede ejecutarse en remoto. Se…
AnalizadaBaja (2.1)0.51%—Fabian Human Resource Integrated System3/8/202517/6/2026
Se encontró una vulnerabilidad en code-projects Human Resource Integrated System 1.0. Se ha clasificado como crítica. Este problema afecta a un procesamiento desconocido del archivo /insert-and-view/action.php. La manipulación del contenido del argumento provoca una inyección SQL. El ataque puede ejecutarse en remoto.…
AplazadaAlta (8.7)2.1%💥 ExploitProcessmaker Open SourceAI31/7/202516/6/2026
Existe una vulnerabilidad de inyección de código en las versiones 2.x de código abierto de ProcessMaker al usar la interfaz predeterminada "neoclassic". Un usuario autenticado puede ejecutar código PHP arbitrario a través de múltiples endpoints, como appFolderAjax.php, casesStartPage_Ajax.php y…
AnalizadaMedia (4.8)0.17%—Oretnom23 Human Resource Management System29/7/202517/6/2026
Cross-Site Scripting (XSS) reflejado en Human Resource Management System version 1.0. Esta vulnerabilidad podría permitir que un atacante ejecute código JavaScript en el navegador de la víctima enviando una URL maliciosa a través del parámetro 'employeeid' en/detailview.php.
Orbitaley — Vulnerabilidades