Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.40%—Codeastro QR Code Attendance Management SystemAI20/9/202621/9/2026
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be…
AplazadaMedia (5.1)0.33%—Akpali9 Attendance-management-systemAI12/7/202613/7/2026
A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date results in cross site scripting. It is possible to initiate the attack remotely.…
AplazadaBaja (2)0.21%—Codeastro Student Attendance Management SystemAI13/6/202623/7/2026
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now…
AplazadaBaja (2.1)0.20%—Codeastro Student Attendance Management SystemAI8/6/202623/7/2026
A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and…
AplazadaBaja (2.1)0.20%—Codeastro Student Attendance Management SystemAI8/6/202623/7/2026
A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public…
AplazadaBaja (2.1)0.20%—Codeastro Student Attendance Management SystemAI8/6/202623/7/2026
A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
AplazadaMedia (5.5)0.27%—Codeastro Student Attendance Management SystemAI8/6/202623/7/2026
A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be…
AplazadaCrítica (9.8)0.80%—Codeastro Simple Attendance Management SystemAI17/4/202617/6/2026
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
AnalizadaAlta (8.8)0.30%—Student Attendance Management System Project Student Attendance Management System7/8/202517/6/2026
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.
AnalizadaAlta (8.8)0.30%—Student Attendance Management System Project Student Attendance Management System7/8/202517/6/2026
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.
AnalizadaAlta (8.8)0.30%—Student Attendance Management System Project Student Attendance Management System7/8/202517/6/2026
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.
AnalizadaAlta (8.8)0.30%—Student Attendance Management System Project Student Attendance Management System7/8/202517/6/2026
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.
AnalizadaAlta (8.8)0.30%—Student Attendance Management System Project Student Attendance Management System7/8/202517/6/2026
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.
AnalizadaMedia (6.1)0.20%—Student Attendance Management System Project Student Attendance Management System7/8/202517/6/2026
Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.
AnalizadaMedia (5.6)0.32%—Kashipara Online Attendance Management System14/2/202517/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.
AnalizadaMedia (5.3)0.64%—Oretnom23 School Intramurals - Student Attendance Management System26/5/202417/6/2026
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_sy.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit…
AnalizadaMedia (5.3)0.49%—Oretnom23 School Intramurals - Student Attendance Management System16/5/202417/6/2026
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack…
AnalizadaMedia (5.3)0.49%—Oretnom23 School Intramurals - Student Attendance Management System16/5/202417/6/2026
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely.…
ModificadaMedia (4.8)0.46%—Student Attendance Management System Project Student Attendance Management System17/11/202217/6/2026
A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed…
ModificadaAlta (7.2)0.56%—Student Attendance Management System Project Student Attendance Management System17/11/202217/6/2026
A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaMedia (5.4)0.55%—Student Attendance Management System Project Student Attendance Management System29/3/202217/6/2026
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via the couse filed in index.php.
ModificadaCrítica (9.8)1.4%—Student Attendance Management System Project Student Attendance Management System29/3/202217/6/2026
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.
ModificadaAlta (7.5)0.93%—Attendance Management System Project Attendance Management System14/2/202217/6/2026
An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).
ModificadaMedia (6.1)0.72%—Attendance Management System Project Attendance Management System26/12/202117/6/2026
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then…
ModificadaCrítica (9.8)2.0%—Attendance Management System Project Attendance Management System1/12/202117/6/2026
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.