Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.69% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Church Management System 1.0. This vulnerability affects unknown code of the file /admin/add_visitor.php. The manipulation of the argument mobile leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.1) | 0.69% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/admin_user.php. The manipulation of the argument firstname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Alta (8.8) | 0.88% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability was found in Campcodes Church Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_sundaysch.php. The manipulation of the argument Gender leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.88% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability was found in Campcodes Church Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/addgiving.php. The manipulation of the argument amount leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.88% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability was found in Campcodes Church Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/addTithes.php. The manipulation of the argument na leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.88% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability was found in Campcodes Church Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/admin_user.php. The manipulation of the argument firstname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.88% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability has been found in Campcodes Church Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/delete_log.php. The manipulation of the argument selector leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.8) | 1.1% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.8) | 1.1% | — | Campcodes Church Management System | 10/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.2) | 0.76% | — | Church Management System Project Church Management System | 30/11/2022 | 17/6/2026 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php. | |
| Modificada | Alta (7.2) | 1.2% | — | Church Management System Project Church Management System | 12/10/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.2) | 0.88% | — | Church Management System Project Church Management System | 15/9/2022 | 17/6/2026 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. | |
| Modificada | Alta (7.2) | 0.88% | — | Church Management System Project Church Management System | 15/9/2022 | 17/6/2026 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. | |
| Modificada | Alta (7.2) | 1.00% | — | Church Management System Project Church Management System | 12/9/2022 | 17/6/2026 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php. | |
| Modificada | Alta (8.8) | 0.75% | — | Church Management System Project Church Management System | 5/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR (SELECT 7064 FROM(SELECT COUNT(*),CONCAT(0x71627a7671,(SELECT… | |
| Modificada | Crítica (9.8) | 1.3% | — | Church Management System Project Church Management System | 13/6/2022 | 17/6/2026 | Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell. | |
| Modificada | Crítica (9.8) | 0.96% | — | ONE Church Management System Project ONE Church Management System | 29/3/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched remotely. | |
| Modificada | Crítica (9.8) | 0.68% | — | ONE Church Management System Project ONE Church Management System | 29/3/2022 | 17/6/2026 | A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely. | |
| Modificada | Media (6.1) | 0.56% | — | ONE Church Management System Project ONE Church Management System | 29/3/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are multiple files and parameters which are prone to to cross site scripting. It is possible to launch the attack remotely. | |
| Modificada | Crítica (9.8) | 4.6% | 💥 PoC | Church Management System Project Church Management System | 29/10/2021 | 17/6/2026 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. | |
| Modificada | Alta (8.8) | 2.7% | 💥 Exploit | Dasinfomedia Wpchurch Church Management System | 28/9/2017 | 17/6/2026 | Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. |