Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.43%—Oretnom23 CAR Driving School Management System12/8/202417/6/2026
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects the function save_package of the file admin/packages/manag_package.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The…
AnalizadaMedia (6.9)0.45%—Oretnom23 CAR Driving School Management System12/8/202417/6/2026
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the function save_users of the file admin/user/index.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.41%—Lopalopa Responsive School Management System8/8/202417/6/2026
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
AnalizadaMedia (4.8)0.51%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field.
AnalizadaCrítica (9.8)0.59%—Lopalopa Responsive School Management System7/8/202417/6/2026
A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
AnalizadaMedia (6.1)0.48%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
ModificadaMedia (6.1)0.46%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
ModificadaMedia (6.1)0.48%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter.
ModificadaMedia (5.3)0.48%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.
AnalizadaMedia (5.3)0.55%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.
AnalizadaMedia (5.3)0.47%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.
ModificadaMedia (5.3)0.51%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.
AnalizadaMedia (6.5)0.39%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration.
ModificadaMedia (6.5)0.45%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.
AnalizadaMedia (5.3)0.64%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.
AnalizadaMedia (5.3)0.54%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.
AnalizadaMedia (5.3)0.43%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.
ModificadaMedia (5.3)0.54%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.
AplazadaMedia (5.3)0.34%—Lahirudanushka School Management SystemAI27/6/202417/6/2026
A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This issue affects some unknown processing of the file /subject.php of the component Subject Page. The manipulation of the argument Subject Title/Sybillus Details leads to cross site scripting. The attack…
ModificadaMedia (5.3)0.55%—Lahirudanushka School Management System24/6/202417/6/2026
A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file examresults-par.php of the component Exam Results Page. The manipulation of the argument sid leads to sql injection. The attack may be launched…
ModificadaMedia (5.1)0.58%—Lahirudanushka School Management System24/6/202417/6/2026
A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file subject.php of the component Subject Page. The manipulation of the argument update leads to sql injection. The attack can be launched…
ModificadaMedia (5.1)0.57%—Lahirudanushka School Management System24/6/202417/6/2026
A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Affected is an unknown function of the file student.php of the component Student Page. The manipulation of the argument update leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaMedia (5.1)0.58%—Lahirudanushka School Management System24/6/202417/6/2026
A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. This issue affects some unknown processing of the file teacher.php of the component Teacher Page. The manipulation of the argument update leads to sql injection. The attack may be initiated…
ModificadaMedia (5.1)0.58%—Lahirudanushka School Management System24/6/202417/6/2026
A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerability affects unknown code of the file parent.php of the component Parent Page. The manipulation of the argument update leads to sql injection. The attack can be initiated remotely. The exploit has…
ModificadaMedia (5.1)0.54%—Lahirudanushka School Management System24/6/202417/6/2026
A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affects an unknown part of the file /attendancelist.php of the component Attendance Report Page. The manipulation of the argument aid leads to sql injection. It is possible to initiate the attack…