Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

5381 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.68%—Nasa Ammos Asynchronous Network Management SystemAI5/8/202626/8/2026
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access…
AplazadaCrítica (9.8)0.75%—Inventory-management-system-phpAI5/8/202626/8/2026
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -.
AplazadaAlta (7.5)0.48%—Book-management-systemAI5/8/202626/8/2026
Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers, the entire student database can be…
AplazadaCrítica (9.8)0.71%—Stock-inventory-management-systemAI5/8/202626/8/2026
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials…
AplazadaMedia (5.5)0.41%—Shandong Hoteam PDM Product Data Management SystemAI5/8/202612/8/2026
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is…
AplazadaMedia (5.5)2.7%—Sangfor Operation AND Maintenance Security Management SystemAI3/8/202612/8/2026
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack…
AplazadaCrítica (9.8)0.54%—Sourcecodester Modern Loan Management SystemAI31/7/202631/8/2026
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.
AplazadaCrítica (9.8)0.42%—Sourcecodester Modern Loan Management SystemAI31/7/20261/10/2026
SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
AplazadaCrítica (9.8)0.32%—Code RO Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeatro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
AplazadaAlta (7.3)0.34%—Sourcecodester Advocate Office Management SystemAI29/7/202630/7/2026
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate…
AplazadaAlta (7.3)0.21%—Kishan0725 Hospital Management SystemAI29/7/20261/10/2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
AplazadaAlta (7.3)0.20%—Kishan0725 Hospital Management SystemAI29/7/20265/10/2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
AplazadaAlta (7.3)0.20%—Kishan0725 Hospital Management SystemAI29/7/20261/10/2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.
AplazadaCrítica (9.8)0.34%—Kishan0725 Hospital Management SystemAI29/7/20261/10/2026
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
AplazadaCrítica (9.8)0.32%—Kishan0725 Hospital Management SystemAI29/7/20265/10/2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
AplazadaCrítica (9.8)0.32%—Kishan0725 Hospital Management SystemAI29/7/20261/10/2026
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.