Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Library Management System Project Library Management System | 27/6/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the component /card/index.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 1.1% | — | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. | |
| Modificada | Media (4.8) | 0.49% | — | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php. | |
| Modificada | Alta (8.8) | 0.97% | — | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated librarian users. | |
| Modificada | Crítica (9.8) | 2.8% | — | Library Management System Project Library Management System | 23/12/2020 | 17/6/2026 | SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system. | |
| Modificada | Crítica (9.8) | 6.5% | — | Online Library Management System Project Online Library Management System | 17/11/2020 | 17/6/2026 | An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root). | |
| Modificada | Alta (7.8) | 0.51% | — | Simple Library Management System Project Simple Library Management System | 22/9/2020 | 9/7/2026 | Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books. | |
| Modificada | Alta (8.4) | 0.57% | — | Simple Library Management System Project Simple Library Management System | 22/9/2020 | 9/7/2026 | Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Library Management System Project Library Management System | 16/11/2018 | 17/6/2026 | Library Management System 1.0 has SQL Injection via the "Search for Books" screen. | |
| Modificada | Alta (8.8) | 0.93% | — | Slims Senayan Library Management System | 6/8/2017 | 17/6/2026 | There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2… | |
| Modificada | Media (4.3) | 4.4% | 💥 Exploit | Softlink Europe Oliver Library Management System | 5/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject arbitrary web script or HTML via the (1) updateform and (2) displayform parameter to (a) gateway/gateway.exe; the (3) TERMS, (4) database, (5) srchad, (6) SuggestedSearch, and (7) searchform… |