Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

5668 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI28/4/202624/7/2026
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The…
AplazadaBaja (2.1)0.32%—Codeastro Online ClassroomAI28/4/202624/7/2026
A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
AplazadaMedia (5.5)0.41%—Sourcecodestr Pharmacy Sales AND Inventory SystemAI27/4/202624/7/2026
A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the…
AplazadaBaja (2.1)0.32%—Codeastro Online ClassroomAI27/4/202617/6/2026
A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AplazadaMedia (6.5)0.21%—Sourcecodester Online JOB Portal PhppdoAI27/4/202617/6/2026
SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.
AplazadaBaja (2)0.38%—Code-projects Online LOT Reservation SystemAI27/4/202617/6/2026
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be used.
AplazadaCrítica (9.8)0.93%—Leonvanzyl AutocoderAI27/4/20265/7/2026
A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.
AplazadaAlta (7.5)0.52%—Leonvanzyl AutocoderAI27/4/202617/6/2026
A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files via sending crafted URL path containing traversal sequences.
AplazadaBaja (2)0.38%—Code-projects Online LOT Reservation SystemAI27/4/202617/6/2026
A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaMedia (5.5)0.63%—Code-projects Online LOT Reservation SystemAI27/4/202617/6/2026
A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used.
AplazadaMedia (5.5)0.41%—Code-projects Online LOT Reservation SystemAI27/4/202617/6/2026
A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI27/4/202617/6/2026
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_category. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and…
AplazadaBaja (2.1)0.45%—Sourcecodester Pharmacy Sales AND Inventory SystemAI27/4/202617/6/2026
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and…
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI27/4/202617/6/2026
A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_type. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed…
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI27/4/202617/6/2026
A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_receiving. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available…
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI27/4/202617/6/2026
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_category. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may…
AplazadaBaja (2.1)0.32%—Code-projects Employee Management SystemAI27/4/202617/6/2026
A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed…
AplazadaBaja (2.1)0.32%—Code-projects Employee Management SystemAI27/4/202617/6/2026
A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and…
AplazadaBaja (2.1)0.47%—Code-projects Employee Management SystemAI27/4/202617/6/2026
A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may…
AplazadaMedia (6.5)0.22%—Codexthemes Thegem Theme ElementsAI27/4/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.
AplazadaBaja (2.1)0.32%—Code-projects Employee Management SystemAI27/4/202617/6/2026
A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
AplazadaBaja (2.1)0.32%—Code-projects Employee Management SystemAI27/4/202617/6/2026
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2)0.33%—Code-projects Invoice SystemAI27/4/202617/6/2026
A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.48%—Code-projects Invoice SystemAILaravelAI27/4/202617/6/2026
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.22%—Code-projects Invoice SystemAI27/4/202617/6/2026
A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.