Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5668 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 28/4/2026 | 24/7/2026 | A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodestr Pharmacy Sales AND Inventory SystemAI | 27/4/2026 | 24/7/2026 | A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the… | |
| Aplazada | Baja (2.1) | 0.32% | — | Codeastro Online ClassroomAI | 27/4/2026 | 17/6/2026 | A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (6.5) | 0.21% | — | Sourcecodester Online JOB Portal PhppdoAI | 27/4/2026 | 17/6/2026 | SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php. | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Crítica (9.8) | 0.93% | — | Leonvanzyl AutocoderAI | 27/4/2026 | 5/7/2026 | A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter. | |
| Aplazada | Alta (7.5) | 0.52% | — | Leonvanzyl AutocoderAI | 27/4/2026 | 17/6/2026 | A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files via sending crafted URL path containing traversal sequences. | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.63% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 27/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_category. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and… | |
| Aplazada | Baja (2.1) | 0.45% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_type. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 27/4/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_receiving. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pharmacy Sales AND Inventory SystemAI | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_category. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may… | |
| Aplazada | Media (6.5) | 0.22% | — | Codexthemes Thegem Theme ElementsAI | 27/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Employee Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.48% | — | Code-projects Invoice SystemAILaravelAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.22% | — | Code-projects Invoice SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |