Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.29% | — | Code-projects Online Music SiteAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Online Music SiteAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Simple Flight Ticket Booking SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /archive1.php. Performing a manipulation of the argument sy results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive2.php. Such manipulation of the argument sy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (1.9) | 0.21% | — | Sourcecodester Hospitals Patient Records Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting. The attack is possible to be carried out remotely. The exploit… | |
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Markdown Preview EnhancedAICrossnoteAIWavedromAIMicrosoft VS CodeAI | 5/6/2026 | 23/7/2026 | Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the… | |
| Aplazada | Media (5.5) | 0.37% | 💥 PoC | Code-projects Vehicle Management SystemAI | 5/6/2026 | 17/6/2026 | A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.26% | — | Code-projects Hotel AND Tourism Reservation SystemAI | 5/6/2026 | 17/6/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (1.9) | 0.21% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.33% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 23/7/2026 | A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Username leads to sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 23/7/2026 | A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and… | |
| Aplazada | Media (6.6) | 0.27% | — | Netty Incubator Codec BhttpAI | 4/6/2026 | 22/7/2026 | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay… | |
| Analizada | Media (6.8) | 0.29% | — | Netty-incubator-codec-ohttp | 4/6/2026 | 22/7/2026 | The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for cryptographic operations versions prior to 0.0.22.Final provide a fallback path for direct ByteBufs that do not… | |
| Analizada | Media (6.9) | 0.32% | — | Netty-incubator-codec-ohttp | 4/6/2026 | 22/7/2026 | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a failure silently… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the argument ef_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Aplazada | Baja (2.1) | 0.27% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Pendiente de análisis | Media (6.3) | 0.71% | — | Python UnicodedataAI | 3/6/2026 | 13/8/2026 | unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. |