Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management System IN PHPAI | 6/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Content Management SystemAI | 6/9/2026 | 8/9/2026 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Vehicle Management SystemAI | 4/9/2026 | 8/9/2026 | A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Vehicle Management SystemAI | 4/9/2026 | 11/9/2026 | A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Kishan0725 Hospital-management-systemAI | 31/8/2026 | 1/9/2026 | A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2) | 0.25% | — | Sambitraj Student Management SystemAI | 31/8/2026 | 31/8/2026 | A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component Password Handler. Executing a manipulation of the argument Password can lead to cleartext storage of sensitive information. The attack can… | |
| Aplazada | Media (5.5) | 0.53% | — | Sambitraj Student-management-systemAI | 31/8/2026 | 31/8/2026 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Aplazada | Baja (2.9) | 0.46% | — | Sambitraj Student-management-systemAI | 31/8/2026 | 31/8/2026 | A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without 'httponly' flag. The attack may be launched remotely. A high complexity level is associated… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Queue Management SystemAI | 30/8/2026 | 31/8/2026 | A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.35% | — | Sambitraj Student Management SystemAI | 30/8/2026 | 1/9/2026 | A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of the component Student Dashboard. The manipulation of the argument roll_no results in improper authorization. The… | |
| Aplazada | Media (6.8) | 0.23% | — | Leyan Medical Practice Management SystemAI | 28/8/2026 | 28/8/2026 | Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files. | |
| Aplazada | Alta (7.1) | 0.80% | — | Personal-management-system Personal Management SystemAI | 27/8/2026 | 24/9/2026 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against… | |
| Aplazada | Alta (8.6) | 0.64% | — | Leyan Medical Practice Management SystemAI | 25/8/2026 | 26/8/2026 | Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page. | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Clinic Management SystemAI | 24/8/2026 | 24/8/2026 | A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Real Estate Management SystemAI | 24/8/2026 | 27/8/2026 | A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Library Management SystemAI | 24/8/2026 | 24/8/2026 | A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.38% | — | Code-projects Barangay Resident Profiling Management SystemAI | 23/8/2026 | 26/8/2026 | A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Barangay Resident Profiling Management SystemAI | 23/8/2026 | 24/8/2026 | A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 0.38% | — | Code-projects Barangay Resident Profiling Management SystemAI | 23/8/2026 | 24/8/2026 | A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the argument resident_id results in authorization bypass. The attack may be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management System ProjectAIPHPAI | 23/8/2026 | 24/8/2026 | A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Stock Management SystemAI | 23/8/2026 | 26/8/2026 | A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Stock Management SystemAI | 23/8/2026 | 24/8/2026 | A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sambitraj Student-management-systemAI | 23/8/2026 | 24/8/2026 | A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of the argument roll_no/name/father_name/class/mobile/email/password/remark causes sql injection. The attack is… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sambitraj Student-management-systemAI | 23/8/2026 | 27/8/2026 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. The manipulation of the argument roll_no/teacher_name results in sql injection. The attack can be executed remotely. The… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 20/8/2026 | 24/8/2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and… |