Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.28% | — | Vishalmathur Cloudclassroom-php-projectAI | 27/9/2026 | 30/9/2026 | A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 0.42% | — | Vishalmathur Cloudclassroom-php-projectAI | 26/9/2026 | 28/9/2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a manipulation of the argument queryx can lead to cross site scripting. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.19% | — | Vishalmathur Cloudclassroom-php-projectAI | 26/9/2026 | 30/9/2026 | A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the… | |
| Analizada | Media (5.5) | 0.50% | — | Vishalmathur Cloudclassroom-php-project | 6/2/2026 | 17/6/2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql injection. The attack is possible to be… | |
| Aplazada | Media (6.5) | 0.24% | — | Vishalmathur Cloudclassroom-php-projectAI | 1/8/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST parameter is not properly sanitized before being used in SQL queries. | |
| Modificada | Media (6.5) | 0.30% | — | Vishalmathur Cloudclassroom-php Project | 25/7/2025 | 5/7/2026 | CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter. | |
| Analizada | Crítica (9.8) | 0.59% | — | Vishalmathur Cloudclassroom-php Project | 20/6/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries. | |
| Analizada | Crítica (9.8) | 0.57% | — | Vishalmathur Cloudclassroom-php Project | 18/6/2025 | 17/6/2026 | CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network… | |
| Analizada | Crítica (9.8) | 0.63% | — | Vishalmathur Cloudclassroom-php Project | 18/6/2025 | 17/6/2026 | CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and… | |
| Analizada | Media (6.1) | 0.39% | — | Vishalmathur Cloudclassroom-php Project | 9/6/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement. | |
| Analizada | Alta (7.3) | 1.1% | — | Vishalmathur Cloudclassroom-php Project | 2/6/2025 | 17/6/2026 | SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries. | |
| Analizada | Alta (7.3) | 0.24% | — | Vishalmathur Cloudclassroom-php Project | 2/6/2025 | 17/6/2026 | A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands. | |
| Analizada | Media (6.1) | 0.49% | — | Vishalmathur Cloudclassroom-php Project | 26/2/2025 | 17/6/2026 | A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function. |