Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Learning Management System | 27/9/2025 | 9/10/2026 | Una vulnerabilidad fue encontrada en Campcodes Online Learning Management System 1.0. Esto afecta una parte desconocida del archivo /admin/edit_student.php. Realizar la manipulación del argumento cys resulta en inyección SQL. El ataque puede ser llevado a cabo remotamente. El exploit ha sido hecho público y podría ser… | |
| Analizada | Baja (2.1) | 0.40% | — | Oranbyte School Management System | 27/9/2025 | 9/10/2026 | Se ha encontrado una falla en ProjectsAndPrograms School Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo owner_panel/fetch-data/select-students.PHP. Esta manipulación del argumento select causa inyección SQL. La explotación remota del ataque es posible. El exploit… | |
| Analizada | Media (5.5) | 0.42% | — | Angeljudesuarez Hostel Management System | 26/9/2025 | 9/10/2026 | Una vulnerabilidad fue detectada en code-projects Hostel Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /justines/admin/mod_users/index.PHP?view=view. La manipulación del argumento ID resulta en inyección SQL. El ataque puede ser ejecutado remotamente. El exploit… | |
| Analizada | Baja (2.1) | 0.34% | — | Angeljudesuarez Online Clinic Management System | 26/9/2025 | 9/10/2026 | Se ha identificado una debilidad en itsourcecode Online Clinic Management System 1.0. Afectada es una función desconocida del archivo /details.php?action=post. La ejecución de la manipulación del argumento ID puede llevar a una inyección SQL. El ataque puede ser lanzado de forma remota. El exploit ha sido puesto a… | |
| Analizada | Media (6.1) | 0.20% | — | Remyandrade Employee Management System | 26/9/2025 | 17/6/2026 | Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.' | |
| Aplazada | Media (5.5) | 0.39% | — | Tutorials-website Employee Management SystemAI | 26/9/2025 | 9/10/2026 | Una vulnerabilidad fue detectada en el Sistema de Gestión de Empleados de Tutorials-Website hasta 611887d8f8375271ce8abc704507d46340837a60. Afectada es una función desconocida del archivo /admin/all-applied-leave.PHP del componente Manejador de Solicitudes HTTP. La manipulación resulta en autorización indebida. El… | |
| Aplazada | Media (5.5) | 0.33% | — | Jackiedyh Resume-management-systemAI | 25/9/2025 | 17/6/2026 | A flaw has been found in JackieDYH Resume-management-system up to fb6b857d852dd796e748ce30c606fe5e61c18273. Affected by this issue is some unknown functionality of the file /admin/show.php. This manipulation of the argument userid causes sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes GYM Management System | 23/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Gym Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may… | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Bookstore Management System | 23/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument unm causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Online Beauty Parlor Management System | 23/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Online Beauty Parlor Management System | 23/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. Affected is an unknown function of the file /admin/view-appointment.php. The manipulation of the argument viewid leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Learning Management System | 22/9/2025 | 17/6/2026 | A weakness has been identified in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_user.php. Executing manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the… | |
| Analizada | Media (5.5) | 0.42% | — | Angeljudesuarez Hostel Management System | 22/9/2025 | 17/6/2026 | A vulnerability was found in code-projects Hostel Management System 1.0. Affected is an unknown function of the file /justines/admin/mod_reports/index.php. The manipulation of the argument Home results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.48% | — | Angeljudesuarez Hostel Management System | 22/9/2025 | 17/6/2026 | A vulnerability has been found in code-projects Hostel Management System 1.0. This impacts an unknown function of the file /justines/admin/mod_amenities/index.php?view=view. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.28% | — | Vibethemes Wordpress Learning Management System | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLMS : from n/a through <= 4.970. | |
| Analizada | Media (5.5) | 0.68% | — | Angeljudesuarez Hostel Management System | 22/9/2025 | 17/6/2026 | A flaw has been found in code-projects Hostel Management System 1.0. This affects an unknown function of the file /justines/admin/mod_comments/index.php?view=view. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be… | |
| Analizada | Media (5.5) | 0.68% | — | Campcodes Online Learning Management System | 22/9/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/edit_user.php. Performing manipulation of the argument firstname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may… | |
| Analizada | Media (5.5) | 0.56% | — | Campcodes Online Learning Management System | 22/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is an unknown function of the file /admin/department.php. Such manipulation of the argument d leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Online Beauty Parlor Management System | 22/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/edit-customer-detailed.php. The manipulation of the argument editid results in sql injection. The attack may be launched remotely. The exploit has been released to… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Online Beauty Parlor Management System | 22/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit is publicly… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Online Beauty Parlor Management System | 22/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Beauty Parlor Management System 1.0. This affects an unknown part of the file /admin/add-services.php. Executing manipulation of the argument sername can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Online Beauty Parlor Management System | 22/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Beauty Parlor Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add-customer.php. Performing manipulation of the argument mobilenum results in sql injection. The attack can be initiated remotely. The exploit has been made public… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Farm Management System | 22/9/2025 | 1/10/2026 | Se ha identificado una debilidad en Campcodes Farm Management System 1.0. Se ve afectada una función desconocida del archivo /uploadProduct.php. Esta manipulación del argumento Type causa inyección SQL. La explotación remota del ataque es posible. El exploit se ha puesto a disposición del público y podría ser… | |
| Analizada | Media (5.4) | 0.26% | — | Phpgurukul Park Ticketing Management System | 22/9/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request. | |
| Analizada | Crítica (9.8) | 0.48% | — | Phpgurukul Park Ticketing Management System | 22/9/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request. |