Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1673 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.76%—Sourcecodester Simple Traffic Offense SystemAI7/9/20268/9/2026
A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The…
AplazadaMedia (5.5)0.69%—Sourcecodester Simple Traffic Offense SystemAI7/9/20269/9/2026
A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/20268/9/2026
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
AplazadaMedia (5.5)0.43%—Sourcecodester Online Voting SystemAI7/9/20268/9/2026
A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and…
AplazadaBaja (2.1)0.23%—Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI7/9/202611/9/2026
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for…
AplazadaMedia (5.5)0.35%—Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI7/9/20268/9/2026
A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly…
AplazadaBaja (2.1)0.40%—Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI7/9/20269/9/2026
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has…
AplazadaBaja (2.1)0.47%—Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI7/9/20268/9/2026
A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The…
AplazadaMedia (5.5)0.52%—Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI7/9/20268/9/2026
A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been…
AplazadaMedia (5.5)0.50%—Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI7/9/20269/9/2026
A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.48%—Sourcecodester Syllabus-aligned Learning Management & Examination SystemAI7/9/20268/9/2026
A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible.…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/20268/9/2026
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/202628/9/2026
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.43%—Itsourcecode School Management SystemAI7/9/202628/9/2026
A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.33%—Itsourcecode Information System Society Membership SystemAI7/9/202628/9/2026
A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/202628/9/2026
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/202611/9/2026
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/20268/9/2026
A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/20269/9/2026
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/20268/9/2026
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI7/9/202628/9/2026
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate the attack remotely. The exploit is now…
AplazadaBaja (2.1)0.33%—Itsourcecode Sales AND Inventory SystemAI6/9/20268/9/2026
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI6/9/20268/9/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI6/9/202611/9/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI6/9/20268/9/2026
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public…
Orbitaley — Vulnerabilidades