Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.34% | — | Oracle Utilities Network Management SystemAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Record Management SystemAI | 15/9/2026 | 22/9/2026 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.52% | — | Subhajitkhan Online-clinic-management-systemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester College Notes Gallery Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester College Notes Gallery Management SystemAI | 15/9/2026 | 15/9/2026 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Hostel Management SystemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Baja (1.9) | 0.37% | — | Phpgurukul Hostel Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester College Notes Gallery Management SystemAI | 15/9/2026 | 15/9/2026 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.9) | 0.31% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on… | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack… | |
| Aplazada | Media (5.5) | 0.69% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Subhajitkhan Online-clinic-management-systemAI | 14/9/2026 | 15/9/2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Leave Management SystemAI | 14/9/2026 | 15/9/2026 | A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.47% | — | Itsourcecode Loan Management SystemAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Leave Management SystemAI | 14/9/2026 | 14/9/2026 | A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public… | |
| Aplazada | Media (5.5) | 0.43% | — | Subhajitkhan Online-clinic-management-systemAI | 14/9/2026 | 14/9/2026 | A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 15/9/2026 | A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 14/9/2026 | A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 16/9/2026 | A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 14/9/2026 | A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Customer_Name leads to cross site scripting. The attack can be executed remotely. The… | |
| Aplazada | Baja (2.1) | 0.24% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published… | |
| Aplazada | Media (5.5) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 14/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper… | |
| Aplazada | Media (5.5) | 0.53% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 16/9/2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 0.69% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.50% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument… |