Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
5381 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.68% | — | Nasa Ammos Asynchronous Network Management SystemAI | 5/8/2026 | 26/8/2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access… | |
| Aplazada | Crítica (9.8) | 0.75% | — | Inventory-management-system-phpAI | 5/8/2026 | 26/8/2026 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -. | |
| Aplazada | Alta (7.5) | 0.48% | — | Book-management-systemAI | 5/8/2026 | 26/8/2026 | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers, the entire student database can be… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Stock-inventory-management-systemAI | 5/8/2026 | 26/8/2026 | The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials… | |
| Aplazada | Media (5.5) | 0.41% | — | Shandong Hoteam PDM Product Data Management SystemAI | 5/8/2026 | 12/8/2026 | A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 2.7% | — | Sangfor Operation AND Maintenance Security Management SystemAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 31/8/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 1/10/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Code RO Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeatro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | |
| Aplazada | Alta (7.3) | 0.34% | — | Sourcecodester Advocate Office Management SystemAI | 29/7/2026 | 30/7/2026 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate… | |
| Aplazada | Alta (7.3) | 0.21% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email. | |
| Aplazada | Alta (7.3) | 0.20% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 5/10/2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. | |
| Aplazada | Alta (7.3) | 0.20% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 5/10/2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. |