Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.4% | — | Os4ed Opensis | 1/9/2020 | 17/6/2026 | SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The fn parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.4% | — | Os4ed Opensis | 1/9/2020 | 17/6/2026 | SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The byear parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.4% | — | Os4ed Opensis | 1/9/2020 | 17/6/2026 | SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bmonth parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.4% | — | Os4ed Opensis | 1/9/2020 | 17/6/2026 | SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bday parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Os4ed Opensis | 24/8/2020 | 17/6/2026 | openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. | |
| Modificada | Alta (7.5) | 68% | 💥 Exploit | Os4ed Opensis | 1/7/2020 | 17/6/2026 | openSIS through 7.4 allows Directory Traversal. | |
| Modificada | Crítica (9.1) | 53% | 💥 Exploit | Os4ed Opensis | 1/7/2020 | 17/6/2026 | openSIS through 7.4 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Os4ed Opensis | 1/7/2020 | 17/6/2026 | openSIS through 7.4 allows SQL Injection. | |
| Modificada | Crítica (9.8) | 2.4% | — | Os4ed Opensis | 1/7/2020 | 17/6/2026 | openSIS before 7.4 allows SQL Injection. | |
| Modificada | Alta (7.5) | 2.1% | — | Os4ed Opensis | 20/10/2014 | 17/6/2026 | SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php. | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Os4ed Opensis | 9/12/2013 | 16/6/2026 | Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter. |