Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

5381 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Hostel Management System22/9/202517/6/2026
A security flaw has been discovered in code-projects Hostel Management System 1.0. The affected element is an unknown function of the file /justines/admin/mod_reservation/index.php?view=view. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit…
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Hostel Management System22/9/202517/6/2026
A vulnerability was determined in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /justines/index.php. This manipulation of the argument log_email causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Hostel Management System22/9/202530/9/2026
Una vulnerabilidad fue identificada en code-projects Hostel Management System 1.0. Afectada es una función desconocida del archivo /justines/admin/mod_roomtype/index.PHP?view=view. Tal manipulación del argumento ID conduce a inyección SQL. El ataque puede ser lanzado remotamente. El exploit está disponible…
AnalizadaMedia (5.5)0.42%—Angeljudesuarez Hostel Management System22/9/202530/9/2026
Una vulnerabilidad fue encontrada en code-projects Hostel Management System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /justines/admin/login.php. La manipulación del argumento email resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit ha sido hecho público y podría ser…
AnalizadaMedia (5.5)0.55%—Campcodes Online Learning Management System22/9/202517/6/2026
A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_subject.php. The manipulation of the argument subject_code leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_subject.php. Executing manipulation of the argument subject_code can lead to sql injection. The attack may be performed from remote. The exploit has been…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/class.php. Performing manipulation of the argument class_name results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A vulnerability was identified in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_class.php. Such manipulation of the argument class_name leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
AnalizadaBaja (2.1)0.34%—Codeastro Simple Pharmacy Management System22/9/202517/6/2026
A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file /view.php. This manipulation of the argument bar_code causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AplazadaMedia (6.4)0.13%—Bimser Solution Software Trade EBA Document AND Workflow Management SystemAI19/9/202517/6/2026
Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing. This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.
AnalizadaMedia (5.5)0.59%—Itsourcecode Student Information Management System18/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed…
AnalizadaBaja (2)0.29%—Facebook-riares Online Petshop Management System18/9/202517/6/2026
A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to launch the attack…
AnalizadaBaja (2)0.29%—Facebook-riares Online Petshop Management System18/9/202517/6/2026
A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The…
AnalizadaBaja (2.1)0.39%—Angeljudesuarez Online Clinic Management System17/9/202517/6/2026
Se ha encontrado una falla en itsourcecode Online Clinic Management System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /editp2.php. La manipulación del argumento id/firstname/lastname/type/age/address puede llevar a una inyección SQL. El ataque puede ejecutarse de forma remota. El exploit ha sido…
AnalizadaMedia (5.5)0.48%—Phpgurukul User Management System17/9/202525/9/2026
Se ha descubierto una falla de seguridad en PHPGurukul User Management System 1.0. Esto afecta una función desconocida del archivo /login.php. Realizar la manipulación del argumento emailid resulta en inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido liberado al público y puede ser explotado.
AnalizadaBaja (2.1)0.49%—Angeljudesuarez Online Clinic Management System17/9/202525/9/2026
Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Clinic Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo transact.php. Tal manipulación del argumento firstname conduce a inyección SQL. El ataque puede ser lanzado de forma remota. El exploit ha…
AnalizadaMedia (5.5)0.48%—Itsourcecode Web-based Internet Laboratory Management System17/9/202525/9/2026
Una falla de seguridad ha sido descubierta en itsourcecode Web-Based Internet Laboratory Management System 1.0. La función afectada es User::AuthenticateUser del archivo login.PHP. La manipulación del argumento user_email conduce a una inyección SQL. La explotación remota del ataque es posible. El exploit ha sido…
AnalizadaBaja (2.1)0.45%—Janobe Online Student File Management System17/9/202525/9/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Student File Management System 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /admin/delete_user.php. La manipulación del argumento user_id lleva a inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido…
AnalizadaBaja (2.1)0.34%—Janobe Online Student File Management System17/9/202525/9/2026
Se ha encontrado una falla en SourceCodester Online Student File Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /admin/delete_student.PHP. La manipulación del argumento stud_id puede llevar a inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha…
AnalizadaBaja (2.1)0.32%—Janobe Online Student File Management System17/9/202525/9/2026
Una vulnerabilidad fue detectada en SourceCodester Online Student File Management System 1.0. Afecta a una función desconocida del archivo /admin/update_student.php. La manipulación del argumento stud_id resulta en inyección SQL. Es posible iniciar el ataque remotamente. El exploit ahora es público y puede ser…
ModificadaMedia (5.4)0.18%—Phpgurukul Auto Taxi Stand Management System16/9/20255/7/2026
A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and…
ModificadaMedia (5.4)0.17%—Fabian Document Management System16/9/20255/7/2026
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.
ModificadaCrítica (9.8)0.56%—Phpgurukul Online Library Management System16/9/20255/7/2026
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function
AnalizadaBaja (2.1)0.43%—Janobe Online Student File Management System15/9/202517/6/2026
A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been…
AnalizadaCrítica (9.8)0.56%—Phpgurukul Online Library Management System15/9/202517/6/2026
An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php