Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 2.6% | 💥 Exploit | Teachers Record Management System Project Teachers Record Management System | 9/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some unknown functionality of the file /changeimage.php of the component Profile Picture Handler. The manipulation of the argument newpic leads to unrestricted upload. The… | |
| Modificada | Media (6.1) | 0.55% | — | Police Crime Record Management System Project Police Crime Record Management System | 2/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Police Crime Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/casedetails.php of the component GET Parameter Handler. The manipulation of the argument id with the input "><script>alert(233)</script>… | |
| Modificada | Crítica (9.8) | 0.73% | — | Police Crime Record Management System Project Police Crime Record Management System | 2/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Police Crime Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /officer/assigncase.php of the component GET Parameter Handler. The manipulation of the argument caseid leads to sql injection. It is possible to initiate… | |
| Modificada | Media (5.4) | 0.55% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 7/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file birthing_print.php. The manipulation of the argument birth_id leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.80% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 7/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.61% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 5/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file hematology_print.php. The manipulation of the argument hem_id leads to cross site scripting. The attack can be… | |
| Modificada | Media (6.1) | 0.56% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 2/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0. This vulnerability affects unknown code of the file admin/fecalysis_form.php. The manipulation of the argument itr_no leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Media (5.4) | 1.1% | 💥 PoC | Record Management System Project Record Management System | 23/11/2022 | 17/6/2026 | An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify user data. | |
| Modificada | Media (4.8) | 1.1% | 💥 PoC | Teacher Record Management System Project Teacher Record Management System | 22/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page. | |
| Modificada | Crítica (9.8) | 0.85% | — | Phpgurukul Employee Record Management System | 28/10/2022 | 17/6/2026 | Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. | |
| Modificada | Media (5.4) | 0.46% | — | Phpgurukul Employee Record Management System | 28/10/2022 | 17/6/2026 | Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Phpgurukul Employee Record Management System | 13/12/2021 | 17/6/2026 | SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system. | |
| Modificada | Alta (7.5) | 2.3% | — | Phpgurukul Employee Record Management System | 13/12/2021 | 17/6/2026 | Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server. | |
| Modificada | Crítica (9.8) | 2.2% | — | Phpgurukul Employee Record Management System | 1/12/2021 | 17/6/2026 | SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php. | |
| Modificada | Crítica (9.8) | 2.9% | — | Phpgurukul Employee Record Management System | 20/7/2021 | 17/6/2026 | SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | |
| Modificada | Media (5.4) | 1.3% | — | Phpgurukul Teachers Record Management System | 1/7/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php. | |
| Modificada | Alta (8.8) | 2.6% | — | Phpgurukul Teachers Record Management System | 1/7/2021 | 17/6/2026 | Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php. | |
| Modificada | Crítica (9.8) | 4.8% | — | Phpgurukul Teachers Record Management System | 15/2/2021 | 17/6/2026 | Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks. |