Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5631 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Student Crud OperationAI | 8/9/2026 | 11/9/2026 | A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Student Crud OperationAI | 8/9/2026 | 28/9/2026 | A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 8/9/2026 | 28/9/2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 11/9/2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible.… | |
| Aplazada | Alta (7.2) | 0.42% | — | Codesigner User Profile BuilderAI | 7/9/2026 | 9/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (6.4) | 0.19% | — | Codesupplyco PowerkitAI | 7/9/2026 | 8/9/2026 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_process_images' function using a flawed regex-based HTML attribute parser. This makes it possible for authenticated… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 7/9/2026 | 8/9/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 11/9/2026 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of… | |
| Aplazada | Media (5.5) | 0.76% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 8/9/2026 | A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.69% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Voting SystemAI | 7/9/2026 | 8/9/2026 | A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 11/9/2026 | A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.35% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.52% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 9/9/2026 | A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.48% | — | Sourcecodester Syllabus-aligned Learning Management & Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Sales AND Inventory SystemAI | 7/9/2026 | 28/9/2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode School Management SystemAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. |