Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.34% | — | Remyandrade Employee Management System | 15/9/2025 | 5/7/2026 | A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department. | |
| Modificada | Alta (8.1) | 0.43% | — | Senior-walter Web-based Pharmacy Product Management System | 15/9/2025 | 5/7/2026 | SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users. | |
| Analizada | Media (5.5) | 0.53% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2.1) | 0.35% | — | Janobe Online Student File Management System | 15/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Media (5.5) | 0.43% | — | Janobe Online Student File Management System | 15/9/2025 | 30/9/2026 | Se ha descubierto una falla de seguridad en SourceCodester Online Student File Management System 1.0. El elemento afectado es una función desconocida del archivo /index.php. Realizar la manipulación del argumento stud_no resulta en inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido liberado al… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/all-appointment.php. The manipulation of the argument delid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be… | |
| Analizada | Alta (7.3) | 0.20% | — | Phpgurukul Student Result Management System | 15/9/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Laundry Management System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Laundry Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.45% | — | Phpgurukul Beauty Parlour Management System | 14/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 30/9/2026 | Se determinó una vulnerabilidad en itsourcecode Baptism Information Management System 1.0. Afectada es una función desconocida del archivo /listbaptism.PHP. Esta manipulación del argumento bapt_id causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser… | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Beauty Parlour Management System | 14/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/readenq.php. Executing manipulation of the argument delid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.34% | — | Oretnom23 Food Ordering Management System | 14/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Impacted is an unknown function of the file /routers/ticket-message.php. Such manipulation of the argument ticket_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2.1) | 0.34% | — | Fcba ZZM Smart Park Management System | 14/9/2025 | 17/6/2026 | A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects unknown code of the file FileUploadUtils.java. The manipulation of the argument File results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and… | |
| Analizada | Baja (2) | 0.43% | — | Fcba ZZM Smart Park Management System | 14/9/2025 | 17/6/2026 | A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of the file ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/JobController.java of the component Scheduled Task Module. Such manipulation leads to code injection. The attack may be performed from… | |
| Aplazada | Baja (2.1) | 0.34% | — | Yida Ecms Consulting Enterprise Management SystemAI | 14/9/2025 | 17/6/2026 | A vulnerability was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the file /login.do of the component POST Request Handler. The manipulation of the argument requestUrl results in cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.36% | — | Shenzhen Sixun Business Management SystemAI | 13/9/2025 | 17/6/2026 | A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of the file /Adm/OperatorStop. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be… | |
| Analizada | Alta (7.2) | 1.6% | 💥 Exploit | Sohamjuhin Tourism Management System | 10/9/2025 | 17/6/2026 | Una vulnerabilidad de carga de shell en Tourism Management System 2.0 permite a un atacante cargar y ejecutar scripts PHP de shell arbitrarios en el servidor, lo que lleva a la ejecución remota de código y acceso no autorizado al sistema. Esto puede resultar en el compromiso de datos sensibles y la funcionalidad del… | |
| Aplazada | Baja (2.1) | 0.25% | — | Hjsoft HCM Human Resources Management SystemAI | 10/9/2025 | 17/6/2026 | A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file /templates/attestation/../../selfservice/lawresource/downlawbase. Performing manipulation of the argument ID results in sql injection. Remote exploitation of… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 9/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 8/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Loan Management System | 8/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. |