Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.25% | — | Codinwithelias School Management SystemAI | 30/11/2025 | 3/9/2026 | A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting. Remote exploitation… | |
| Modificada | Baja (2) | 0.22% | — | Phpgurukul Hostel Management System | 24/11/2025 | 8/10/2026 | Se ha encontrado una vulnerabilidad en PHPGurukul Hostel Management System 2.1. El elemento afectado es una función desconocida del archivo /register-complaint.PHP. La ejecución de una manipulación del argumento cdetails puede conducir a cross-site scripting. Es posible lanzar el ataque de forma remota. El exploit ha… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 23/11/2025 | 8/10/2026 | Una falla de seguridad ha sido descubierta en projectworlds puede pasar cargas útiles maliciosas hasta 1.0. Esta vulnerabilidad afecta código desconocido del archivo /add_book.php. La manipulación del argumento image resulta en subida irrestricta. El ataque puede ser ejecutado remotamente. El exploit ha sido publicado… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Advanced Library Management System | 23/11/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en projectworlds Advanced Biblioteca Management System 1.0. Esto afecta una parte desconocida del archivo /delete_admin.php. La manipulación del argumento admin_id conduce a inyección SQL. La explotación remota del ataque es posible. El exploit está disponible públicamente y podría… | |
| Analizada | Media (5.5) | 0.47% | — | Warren-daloyan Inventory Management System | 23/11/2025 | 8/10/2026 | Se ha identificado una debilidad en SourceCodester Inventory Management System 1.0. El elemento afectado es una función desconocida del archivo /model/user/resetPassword.PHP. La ejecución de manipulación puede llevar a una recuperación de contraseña débil. El ataque puede realizarse de forma remota. El exploit ha sido… | |
| Analizada | Baja (2.1) | 0.37% | — | Kimz190 Pre-school Management System | 23/11/2025 | 8/10/2026 | Se ha descubierto una falla de seguridad en SourceCodester Pre-School Management System 1.0. Afectada es la función removefile del archivo app/controllers/FilehelperController.PHP. La manipulación del argumento filepath resulta en denegación de servicio. El ataque puede ser llevado a cabo de forma remota. El exploit… | |
| Modificada | Media (5.5) | 0.39% | — | Campcodes School File Management System | 23/11/2025 | 17/6/2026 | A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Supplier Management System | 23/11/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Online Beauty Parlor Management System | 20/11/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and… | |
| Analizada | Media (5.5) | 0.37% | — | Admerc File Management System | 20/11/2025 | 7/10/2026 | Una falla de seguridad ha sido descubierta en itsourcecode Online File Management System 1.0. Este problema afecta algún procesamiento desconocido del archivo /ajax.PHP?action=login. La manipulación del argumento Username resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit ha sido liberado al… | |
| Analizada | Baja (2.1) | 0.38% | — | Oretnom23 Alumni Management System | 20/11/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead to missing… | |
| Analizada | Baja (2) | 0.38% | — | Campcodes Supplier Management System | 20/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument txtProductName leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.5) | 0.44% | — | Darkseid Sports Club Management System | 20/11/2025 | 17/6/2026 | A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown function of the file /dashboard/admin/change_s_pwd.php. Performing manipulation of the argument login_id results in sql injection. The attack may be initiated remotely. The exploit is now public and… | |
| Analizada | Media (5.5) | 0.39% | — | Angeljudesuarez Human Resource Management System | 19/11/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argument noticeDesc leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Media (5.5) | 0.39% | — | Angeljudesuarez Human Resource Management System | 19/11/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argument eventSubject causes sql injection. The attack can be initiated remotely. The exploit has been made available to the… | |
| Analizada | Alta (7.3) | 0.20% | — | Campcodes Online Hospital Management System | 19/11/2025 | 17/6/2026 | Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username. | |
| Analizada | Baja (2.1) | 0.32% | — | Carmelogarcia Courier Management System | 19/11/2025 | 17/6/2026 | A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119. | |
| Analizada | Media (6.1) | 0.20% | — | Kishan0725 Hospital Management System | 18/11/2025 | 17/6/2026 | kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter. | |
| Analizada | Media (6.5) | 0.27% | — | Kishan0725 Hospital Management System | 18/11/2025 | 17/6/2026 | kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. | |
| Analizada | Media (6.5) | 0.24% | — | Kishan0725 Hospital Management System | 18/11/2025 | 17/6/2026 | kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into a dynamic SQL query. | |
| Modificada | Media (6.8) | 0.36% | 💥 PoC | Remyandrade Student Grades Management System | 18/11/2025 | 5/7/2026 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument name/description causes stored cross site scripting. | |
| Analizada | Baja (2) | 0.26% | — | Remyandrade Student Grades Management System | 18/11/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades.php of the component Add New Grade Page. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The… | |
| Analizada | Baja (2) | 0.38% | — | Janobe Interview Management System | 18/11/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php. The manipulation of the argument Question results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Analizada | Baja (2.1) | 0.37% | — | Carmelogarcia Courier Management System | 17/11/2025 | 7/10/2026 | Se determinó una vulnerabilidad en code-projects Courier Management System 1.0. Este problema afecta a alguna funcionalidad desconocida del archivo /search-edit.php. Esta manipulación del argumento Consignment causa inyección SQL. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado públicamente y… |