Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
308 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.26% | — | Code-projects Online Class AND Exam Scheduling System | 24/4/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks. | |
| Analizada | Media (6.5) | 0.26% | — | Code-projects Online Class AND Exam Scheduling System | 24/4/2025 | 17/6/2026 | A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks. | |
| Analizada | Media (4.8) | 0.24% | — | Code-projects Online Class AND Exam Scheduling System | 24/4/2025 | 17/6/2026 | A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS). | |
| Analizada | Media (6.3) | 0.61% | — | Yxj2018 Springboot-vue-onlineexam | 22/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack may be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (5.3) | 0.37% | — | Yxj2018 Springboot-vue-onlineexam | 22/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.1) | 0.90% | 💥 Exploit | Code-projects Online Exam Mastering System | 21/4/2025 | 17/6/2026 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.49% | — | Nayem-howlader Online Exam System | 28/3/2025 | 17/6/2026 | Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php. | |
| Analizada | Media (5.1) | 0.41% | — | Code-projects Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/salut_del.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (4.6) | 0.21% | — | Code-projects Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters. | |
| Analizada | Media (5.1) | 0.50% | — | Fabian Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/activate.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.79% | — | Carmelo Online Exam Mastering System | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter | |
| Analizada | Media (5.9) | 0.26% | — | Fabian Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters. | |
| Analizada | Media (5.5) | 0.24% | — | Fabian Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first. | |
| Analizada | Media (4.1) | 0.28% | — | Fabian Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters. | |
| Analizada | Media (6.1) | 0.27% | — | Fabian Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters. | |
| Analizada | Baja (3.2) | 0.20% | — | Code-projects Online Class AND Exam Scheduling System | 17/3/2025 | 17/6/2026 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters. | |
| Analizada | Media (5.1) | 0.38% | — | Code-projects Online Class AND Exam Scheduling System | 4/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the argument username leads to cross site scripting. The attack may be… | |
| Aplazada | Media (6.1) | 0.33% | — | Sunnygkp10 Online Exam SystemAI | 17/1/2025 | 5/7/2026 | Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter. | |
| Aplazada | Alta (7.1) | 0.20% | — | Dutch VAN Andel Custom List Table ExampleAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dutch van Andel Custom List Table Example custom-list-table-example allows Reflected XSS.This issue affects Custom List Table Example: from n/a through <= 1.4.1. | |
| Analizada | Media (6.3) | 0.77% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The… | |
| Analizada | Media (5.3) | 0.62% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to… | |
| Analizada | Media (6.9) | 0.57% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Tecnick TcexamAI | 30/12/2024 | 17/6/2026 | Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |
| Aplazada | Alta (7.5) | 0.50% | — | Tecnick TcexamAI | 30/12/2024 | 17/6/2026 | Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Analizada | Media (5.3) | 0.39% | — | Code-projects Online Exam Mastering System | 22/12/2024 | 17/6/2026 | A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file /sign.php?q=account.php. The manipulation of the argument name/gender/college leads to cross site scripting. The attack can be launched remotely.… |