Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2523▼ 417 respecto a la semana anterior
Críticas / altas1297▲ 13 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.31% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on… | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack… | |
| Aplazada | Media (5.5) | 0.69% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Media (5.3) | 0.37% | — | Specterops BloodhoundAI | 3/9/2026 | 4/9/2026 | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading… | |
| Aplazada | Media (6.1) | 0.18% | — | Code-projects Blood SystemAI | 30/7/2026 | 1/10/2026 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. | |
| Aplazada | Alta (7.1) | 0.44% | — | BloodhoundAI | 15/7/2026 | 17/9/2026 | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens can create, update, or delete custom node types affecting all users and tenants… | |
| Aplazada | Media (5.5) | 0.26% | — | Itsourcecode Online Blood Bank Management SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.27% | — | Itsourcecode Online Blood Bank Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.35% | — | Code-projects Bloodbank Managing SystemAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Bloodbank Managing SystemAI | 4/5/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation of the argument G_STATE_ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Bloodbank Managing SystemAI | 1/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Media (6.9) | 0.32% | — | BloodxAI | 11/2/2026 | 17/6/2026 | BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with '=''or' parameters to bypass login authentication and gain unauthorized access. | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Simple Blood Donor Management System | 6/2/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Simple Blood Donor Management System | 19/12/2025 | 17/6/2026 | A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unknown function of the file /editedcampaign.php. The manipulation of the argument campaignname results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Simple Blood Donor Management System | 19/12/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unknown function of the file /editeddonor.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and… | |
| Analizada | Alta (8.8) | 0.39% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain… | |
| Analizada | Media (5.4) | 0.22% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg and error parameters,… | |
| Analizada | Media (5.4) | 0.22% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and rprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the… | |
| Analizada | Alta (8.8) | 0.39% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and… | |
| Analizada | Crítica (9.8) | 0.65% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass… | |
| Analizada | Alta (8.8) | 0.37% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling… | |
| Analizada | Media (5.4) | 0.33% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the error parameter, which… | |
| Analizada | Media (5.4) | 0.33% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the… | |
| Analizada | Media (5.4) | 0.33% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg parameter, which is then… | |
| Modificada | Alta (8.8) | 0.49% | — | Shridharshukl Blood Bank Management System | 1/12/2025 | 17/6/2026 | An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php. |