Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

118 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)2.6%💥 ExploitTeachers Record Management System Project Teachers Record Management System9/6/202317/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some unknown functionality of the file /changeimage.php of the component Profile Picture Handler. The manipulation of the argument newpic leads to unrestricted upload. The…
ModificadaMedia (6.1)0.55%—Police Crime Record Management System Project Police Crime Record Management System2/4/202317/6/2026
A vulnerability was found in SourceCodester Police Crime Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/casedetails.php of the component GET Parameter Handler. The manipulation of the argument id with the input "><script>alert(233)</script>…
ModificadaCrítica (9.8)0.73%—Police Crime Record Management System Project Police Crime Record Management System2/4/202317/6/2026
A vulnerability was found in SourceCodester Police Crime Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /officer/assigncase.php of the component GET Parameter Handler. The manipulation of the argument caseid leads to sql injection. It is possible to initiate…
ModificadaMedia (5.4)0.55%—Health Center Patient Record Management System Project Health Center Patient Record Management System7/3/202317/6/2026
A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file birthing_print.php. The manipulation of the argument birth_id leads to cross site scripting. The attack can be initiated remotely. The…
ModificadaCrítica (9.8)0.80%—Health Center Patient Record Management System Project Health Center Patient Record Management System7/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (6.1)0.61%—Health Center Patient Record Management System Project Health Center Patient Record Management System5/3/202317/6/2026
A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file hematology_print.php. The manipulation of the argument hem_id leads to cross site scripting. The attack can be…
ModificadaMedia (6.1)0.56%—Health Center Patient Record Management System Project Health Center Patient Record Management System2/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0. This vulnerability affects unknown code of the file admin/fecalysis_form.php. The manipulation of the argument itr_no leads to cross site scripting. The attack can be initiated remotely. The…
ModificadaMedia (5.4)1.1%💥 PoCRecord Management System Project Record Management System23/11/202217/6/2026
An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify user data.
ModificadaMedia (4.8)1.1%💥 PoCTeacher Record Management System Project Teacher Record Management System22/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.
ModificadaCrítica (9.8)0.85%—Phpgurukul Employee Record Management System28/10/202217/6/2026
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
ModificadaMedia (5.4)0.46%—Phpgurukul Employee Record Management System28/10/202217/6/2026
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
ModificadaCrítica (9.8)2.1%—Phpgurukul Employee Record Management System13/12/202117/6/2026
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.
ModificadaAlta (7.5)2.3%—Phpgurukul Employee Record Management System13/12/202117/6/2026
Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.
ModificadaCrítica (9.8)2.2%—Phpgurukul Employee Record Management System1/12/202117/6/2026
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.
ModificadaCrítica (9.8)2.9%—Phpgurukul Employee Record Management System20/7/202117/6/2026
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
ModificadaMedia (5.4)1.3%—Phpgurukul Teachers Record Management System1/7/202117/6/2026
A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.
ModificadaAlta (8.8)2.6%—Phpgurukul Teachers Record Management System1/7/202117/6/2026
Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.
ModificadaCrítica (9.8)4.8%—Phpgurukul Teachers Record Management System15/2/202117/6/2026
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.
Orbitaley — Vulnerabilidades