Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
5667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.30% | — | CodexbarAI | 1/6/2026 | 22/7/2026 | CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp and Ollama provider sessions. Attackers can position themselves on the network path to receive cleartext HTTP requests… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Computer Repair Shop Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Real State ServicesAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (5.5) | 0.26% | — | Codeastro Online JOB PortalAI | 1/6/2026 | 22/7/2026 | A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Codeastro Online JOB PortalAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.31% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.33% | — | Sourcecodester PET Grooming Management SoftwareAI | 1/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online House Rental SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online House Rental SystemAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online House Rental SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online Blood Bank Management SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.27% | — | Itsourcecode Online Blood Bank Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.25% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2) | 0.20% | — | Sourcecodestar Pharmacy Sales AND Inventory SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be… | |
| Aplazada | Media (5.5) | 0.63% | 💥 PoC | Code-projects Smart Parking SystemAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple… | |
| Aplazada | Baja (2.1) | 0.25% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2) | 0.26% | — | Sourcecodester Water Billing Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management Module. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.37% | — | Sourcecodester Water Billing Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been… |