Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.35% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 20/8/2026 | 24/8/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely. | |
| Aplazada | Baja (2.9) | 0.40% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 3/7/2026 | 6/7/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 3/7/2026 | 7/7/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote… | |
| Aplazada | Media (6.9) | 0.28% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 17/6/2026 | 18/6/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack… | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 14/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.42% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 26/5/2026 | 24/7/2026 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote.… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 26/5/2026 | 24/7/2026 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.45% | 💥 PoC | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 29/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site… |