Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

272 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5)0.26%—Codeastro BUS Ticket Booking System28/4/202517/6/2026
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
AnalizadaMedia (6.9)0.56%—Codeastro Membership Management System28/4/202517/6/2026
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaCrítica (9.8)0.54%—Codeastro BUS Ticket Booking System25/4/202517/6/2026
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
AnalizadaAlta (8)0.27%—Codeastro BUS Ticket Booking System24/4/202517/6/2026
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
AnalizadaAlta (7.8)0.28%—Astrolog18/4/202517/6/2026
A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.
AnalizadaMedia (6.1)0.30%💥 PoCCodeastro Internet Banking System17/4/202517/6/2026
Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
AnalizadaAlta (8.8)0.88%💥 PoCCodeastro Internet Banking System10/4/202517/6/2026
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
AnalizadaMedia (4.8)0.27%💥 PoCCodeastro Internet Banking System9/4/202517/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.
AnalizadaMedia (5.3)0.47%—Codeastro Student Grading System4/4/202517/6/2026
A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The manipulation of the argument studentId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.50%—Codeastro CAR Rental System4/4/202517/6/2026
A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of the file /returncar.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaAlta (7.5)0.69%💥 PoCCodeastro Complaint Management System6/2/202517/6/2026
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.
AnalizadaAlta (7.3)0.45%💥 PoCCodeastro Internet Banking System22/1/202517/6/2026
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This…
AnalizadaCrítica (9.8)0.61%—Codeastro Complaint Management System3/1/202517/6/2026
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
AnalizadaMedia (5.3)0.55%—Codeastro Online Food Ordering System31/12/202417/6/2026
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_users.php of the component Update User Page. The manipulation of the argument user_upd leads to sql injection. The attack can be…
AnalizadaMedia (6.9)0.85%—Codeastro Online Food Ordering System31/12/202417/6/2026
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (6.9)0.80%—Codeastro Simple Loan Management System30/12/202417/6/2026
A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (5.3)0.58%—Codeastro CAR Rental System27/12/202417/6/2026
A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bookingconfirm.php. The manipulation of the argument driver_id_from_dropdown leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.68%—Codeastro House Rental Management System26/12/202417/6/2026
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signin.php. The manipulation of the argument u/p leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.68%—Codeastro House Rental Management System26/12/202417/6/2026
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ownersignup.php. The manipulation of the argument f/e/p/m/o/n/c/s/ci/a leads to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (5.3)0.48%—Codeastro Blood Donor Management System26/12/202417/6/2026
A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AnalizadaCrítica (9.8)0.82%—Codeastro Complaint Management System20/12/202417/6/2026
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
AnalizadaAlta (7.8)1.5%💥 ExploitAstro19/12/202417/6/2026
Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such as css and font files, the sourcemap files **for the server code** are moved to a publicly-accessible folder. Any outside…
AnalizadaAlta (8.8)0.70%—Codeastro Complaint Management System18/12/202417/6/2026
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.
AnalizadaAlta (8.8)0.70%—Codeastro Complaint Management System18/12/202417/6/2026
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.
AnalizadaMedia (6.5)0.22%—Astro18/12/202417/6/2026
Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF checks. When the `security.checkOrigin` configuration option is set to `true`, Astro middleware will perform a CSRF check. However, a vulnerability exists that can…
Orbitaley — Vulnerabilidades