Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1673 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.76% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 8/9/2026 | A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.69% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Voting SystemAI | 7/9/2026 | 8/9/2026 | A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 11/9/2026 | A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.35% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.52% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 9/9/2026 | A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.48% | — | Sourcecodester Syllabus-aligned Learning Management & Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 28/9/2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode School Management SystemAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Information System Society Membership SystemAI | 7/9/2026 | 28/9/2026 | A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 28/9/2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 11/9/2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 6/9/2026 | 8/9/2026 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 11/9/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public… |