Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2714▼ 164 respecto a la semana anterior
Críticas / altas1235▼ 317 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.74%—Sales Tracker Management System Project Sales Tracker Management System11/4/202317/6/2026
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The…
ModificadaMedia (6.1)0.88%—Sales Tracker Management System Project Sales Tracker Management System10/4/202317/6/2026
Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file.
ModificadaAlta (7.5)1.4%—Sales Tracker Management System Project Sales Tracker Management System10/4/202317/6/2026
An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.
ModificadaAlta (7.5)0.58%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP5/4/202317/6/2026
A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997…
ModificadaCrítica (9.8)0.74%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP31/3/202317/6/2026
A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this…
ModificadaMedia (6.1)0.36%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP29/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated…
ModificadaMedia (6.1)0.36%—Earnings AND Expense Tracker APP Project Earnings AND Expense Tracker APP29/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnerability affects unknown code of the file Master.php?a=save_earning. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The identifier of this…
ModificadaMedia (6.1)0.36%—Oretnom23 Earnings AND Expense Tracker Application29/3/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated…
ModificadaCrítica (9.8)0.79%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/username/password leads to improper authentication. It is possible to initiate the…
ModificadaMedia (6.1)0.39%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Medicine Tracker System 1.0. Affected by this issue is some unknown functionality of the file app/?page=medicines/manage_medicine. The manipulation of the argument name/description with the input <script>alert('2')</script> leads to…
ModificadaCrítica (9.8)0.81%—Medicine Tracker System Project Medicine Tracker System17/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracker System 1.0. This issue affects some unknown processing of the file medicines/view_details.php of the component GET Parameter Handler. The manipulation of the argument GET leads to sql injection. The attack may be…
ModificadaMedia (6.1)0.60%—File Tracker Manager System Project File Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester File Tracker Manager System 1.0. This affects an unknown part of the file normal/borrow1.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to initiate…
ModificadaCrítica (9.8)0.82%—File Tracker Manager System Project File Tracker Management System9/3/202317/6/2026
A vulnerability was found in SourceCodester File Tracker Manager System 1.0. It has been classified as critical. Affected is an unknown function of the file /file_manager/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to launch the…
ModificadaCrítica (9.8)0.76%—Sales Tracker Management System Project Sales Tracker Management System9/3/202317/6/2026
A vulnerability has been found in SourceCodester Sales Tracker Management System 1.0 and classified as critical. This vulnerability affects the function delete_client of the file classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.76%—Sales Tracker Management System Project Sales Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/clients/manage_client.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.76%—Sales Tracker Management System Project Sales Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Sales Tracker Management System 1.0. Affected by this issue is some unknown functionality of the file admin/clients/view_client.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The…
ModificadaAlta (8.8)0.49%—Sales Tracker Management System Project Sales Tracker Management System24/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)0.54%—Sales Tracker Management System Project Sales Tracker Management System23/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/?page=user/manage_user of the component Edit User. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaAlta (8.1)0.49%—Sales Tracker Management System Project Sales Tracker Management System22/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. Affected is an unknown function of the file admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack…
ModificadaMedia (5.3)0.61%—Schismtracker Schism Tracker17/2/202317/6/2026
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c.
ModificadaCrítica (9.8)0.62%—Stracker Project Stracker15/1/202317/6/2026
Una vulnerabilidad fue encontrada en visegripped Stracker y clasificada como crítica. La función getHistory del archivo doc_root/public_html/stracker/api.php es afectada por esta vulnerabilidad. La manipulación del argumento symbol/startDate/endDate conduce a la inyección de SQL. El identificador del parche es…
ModificadaCrítica (9.8)0.64%—Cub-scout-tracker Project Cub-scout-tracker6/1/202317/6/2026
Se ha encontrado una vulnerabilidad en Seiji42 cub-scout-tracker y se ha clasificado como crítica. Una parte desconocida del archivo DatabaseAccessFunctions.js afecta a una parte desconocida. La manipulación conduce a la inyección SQL. El parche se llama b4bc1a328b1f59437db159f9d136d9ed15707e31. Se recomienda aplicar…
ModificadaAlta (8.8)0.34%—Openacs Bug-tracker5/1/202317/6/2026
Se ha encontrado una vulnerabilidad en OpenACS bug-tracker y ha sido clasificada como problemática. Una función desconocida del archivo lib/nav-bar.adp del componente Search es afectada por esta vulnerabilidad. La manipulación conduce a cross-site request forgery. Es posible lanzar el ataque de forma remota. El nombre…
ModificadaMedia (6.1)0.57%—Rivettracker Project Rivettracker3/1/202316/6/2026
Se ha encontrado una vulnerabilidad en ahmyi RivetTracker y se ha clasificado como problemática. Este problema afecta algún procesamiento desconocido. La manipulación del argumento $_SERVER['PHP_SELF'] conduce a cross-site scripting. El ataque puede iniciarse de forma remota. El parche se llama…
ModificadaMedia (6.1)0.52%—Rivettracker Project Rivettracker3/1/202316/6/2026
Se encontró una vulnerabilidad en ahmyi RivetTracker. Ha sido declarada problemática. La función changeColor del archivo css.php es afectada por esta vulnerabilidad. La manipulación del argumento set_css conduce a cross-site scripting. El ataque se puede lanzar de forma remota. El parche se llama…