Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

22.765 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Apcu ManagerAI29/6/202629/6/2026
The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another…
AplazadaBaja (2.1)0.23%—Codeastro Human Resource Management SystemAI29/6/202629/6/2026
A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.33%—Codeastro Human Resource Management SystemAI29/6/202629/6/2026
A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This manipulation of the argument deptid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument editid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202630/6/2026
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit is…
AplazadaBaja (2.1)0.33%—Codeastro Human Resource Management SystemAI29/6/202629/6/2026
A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql injection. The attack can be launched…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaBaja (2)0.35%—Code-projects Project Management SystemAI28/6/202630/6/2026
A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may…
AplazadaBaja (2.1)0.47%—Yashpokharna2555 Restaurent-management-systemAI28/6/202629/6/2026
A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The attack may be initiated remotely. The…
AplazadaMedia (5.5)0.43%—Yashpokharna2555 Restaurent-management-systemAI28/6/202630/6/2026
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit is publicly…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI28/6/202629/6/2026
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI28/6/202629/6/2026
A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
AplazadaBaja (2)0.35%—Itsourcecode Hospital Management SystemAI28/6/202629/6/2026
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument loginid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AplazadaAlta (8.1)0.60%—Najeebmedia Frontend File ManagerAI28/6/202629/6/2026
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase…
AnalizadaAlta (7.2)0.50%—Devolutions Remote Desktop Manager26/6/202629/6/2026
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing…
AplazadaMedia (5.3)0.29%—Booking AND Rental ManagerAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
AplazadaMedia (6.5)0.30%—Wpaffiliatemanager Affiliates ManagerAI26/6/202629/6/2026
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
AplazadaCrítica (9.3)0.40%—Library Management SystemAI26/6/202629/6/2026
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
AplazadaAlta (7.5)0.42%—Johnson AND Johnson Audit Tracking Management SystemAI26/6/202626/6/2026
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
AnalizadaCrítica (10)0.39%—Wso2 API Manager26/6/202627/6/2026
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful…
AplazadaMedia (6.5)0.47%💥 PoCNajeebmedia Frontend File ManagerAI26/6/202626/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin…
AplazadaAlta (7.7)0.22%💥 PoCGrocery Store Management System Using PHP AND Mysql PhpmyadminAI25/6/202626/6/2026
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
AnalizadaAlta (7.8)0.82%—Dell Display AND Peripheral Manager25/6/20265/8/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.