Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.50% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.39% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 14/9/2026 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.57% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 16/9/2026 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.37% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 19/9/2026 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Alta (7.5) | 0.50% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 10/9/2026 | A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.76% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 10/9/2026 | A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 11/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes… | |
| Aplazada | Media (5.5) | 0.69% | — | Rizwan17 Inventory Management SystemAI | 9/9/2026 | 10/9/2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 14/9/2026 | A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible… | |
| Aplazada | Baja (2.1) | 0.38% | — | Ningzichun Student Management SystemAI | 8/9/2026 | 11/9/2026 | A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.47% | — | Ningzichun Student Management SystemAI | 8/9/2026 | 8/9/2026 | A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated… | |
| Aplazada | Media (5.5) | 0.48% | — | Ningzichun Student Management SystemAI | 8/9/2026 | 11/9/2026 | A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.55% | — | Jaychouchannel Tourism-management-systemAI | 7/9/2026 | 8/9/2026 | A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName… | |
| Aplazada | Media (5.5) | 0.45% | — | Jaychouchannel Tourism Management SystemAI | 7/9/2026 | 8/9/2026 | A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode School Management SystemAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.36% | — | Mstfakts College-management-systemAI | 6/9/2026 | 9/9/2026 | A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.65% | — | Mstfakts College Management SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.… | |
| Aplazada | Media (5.5) | 0.43% | — | Mstfakts College-management-systemAI | 6/9/2026 | 10/9/2026 | A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 0.41% | — | Rabindralamsal Inventory-management-systemAI | 6/9/2026 | 8/9/2026 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.36% | — | Code-projects Task Management SystemAI | 6/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The… |