Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
3978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.34% | — | Janobe Online Exam Form Submission | 17/9/2025 | 25/9/2026 | Se encontró una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /admin/delete_s1.PHP. Realizar la manipulación del argumento ID resulta en inyección SQL. El ataque puede iniciarse remotamente. El exploit se ha hecho público… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Online Exam Form Submission | 17/9/2025 | 25/9/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Afecta a una función desconocida del archivo /admin/index.php. Dicha manipulación del argumento email conduce a inyección SQL. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser… | |
| Analizada | Media (5.5) | 0.46% | — | Janobe Online Exam Form Submission | 17/9/2025 | 25/9/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Esto afecta a una función desconocida del archivo /register.PHP. Esta manipulación del argumento 'img' provoca una carga sin restricciones. Es posible iniciar el ataque de forma remota. El exploit ha sido publicado y puede ser… | |
| Analizada | Media (5.5) | 0.55% | — | Janobe Online Exam Form Submission | 17/9/2025 | 25/9/2026 | Se encontró una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Esto afecta una parte desconocida del archivo /index.php. La manipulación del argumento usn resulta en inyección SQL. El ataque puede lanzarse remotamente. El exploit se ha hecho público y podría utilizarse. | |
| Analizada | Baja (2.1) | 0.45% | — | Janobe Online Student File Management System | 17/9/2025 | 25/9/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Student File Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /admin/delete_user.php. La manipulación del argumento user_id lleva a inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido… | |
| Analizada | Baja (2.1) | 0.34% | — | Janobe Online Student File Management System | 17/9/2025 | 25/9/2026 | Se ha encontrado una falla en SourceCodester Online Student File Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /admin/delete_student.PHP. La manipulación del argumento stud_id puede llevar a inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha… | |
| Analizada | Baja (2.1) | 0.32% | — | Janobe Online Student File Management System | 17/9/2025 | 25/9/2026 | Una vulnerabilidad fue detectada en SourceCodester Online Student File Management System 1.0. Afecta a una función desconocida del archivo /admin/update_student.php. La manipulación del argumento stud_id resulta en inyección SQL. Es posible iniciar el ataque remotamente. El exploit ahora es público y puede ser… | |
| Analizada | Baja (2.1) | 0.39% | — | Itsourcecode Online Public Access Catalog | 17/9/2025 | 25/9/2026 | Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Public Access Catalog OPAC 1.0. Esto afecta a una función desconocida del archivo mysearch.php del componente POST Parameter Handler. Dicha manipulación del argumento search_field/search_text conduce a inyección SQL. El ataque puede ser realizado… | |
| Modificada | Crítica (9.8) | 0.56% | — | Phpgurukul Online Library Management System | 16/9/2025 | 5/7/2026 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function | |
| Analizada | Baja (2.1) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.56% | — | Phpgurukul Online Library Management System | 15/9/2025 | 17/6/2026 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php | |
| Analizada | Media (5.5) | 0.53% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2.1) | 0.35% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Media (5.5) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 30/9/2026 | Se ha descubierto una falla de seguridad en SourceCodester Online Student File Management System 1.0. El elemento afectado es una función desconocida del archivo /index.php. Realizar la manipulación del argumento stud_no resulta en inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido liberado al… | |
| Analizada | Media (5.5) | 0.53% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php?q=result&searchfor=bycompany. This manipulation of the argument Search causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.46% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform.php. The manipulation of the argument picture results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.50% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Online Job Finder System 1.0. This issue affects some unknown processing of the file /advancesearch.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Laundry Management System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Laundry Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.49% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the argument new_image leads to unrestricted upload. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.46% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the argument new_image causes unrestricted upload. The attack is possible to be… | |
| Analizada | Media (6.1) | 0.23% | — | Phpgurukul Online Shopping Portal | 12/9/2025 | 17/6/2026 | PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart. | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This vulnerability could allow a remote user… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint '/ofrs/admin/request-details.php'. This vulnerability could allow a… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'. This vulnerability could allow a remote… |