Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.32%—Oretnom23 Computer Laboratory Management System8/3/202617/6/2026
A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.
AnalizadaAlta (8.8)0.49%—Oretnom23 Computer Laboratory Management System29/4/202517/6/2026
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter
AnalizadaMedia (5.3)0.38%—Campcodes Computer Laboratory Management System9/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0. This affects an unknown part of the file /class/edit/edit. The manipulation of the argument s_lname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.47%—Campcodes Computer Laboratory Management System9/1/202517/6/2026
A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is some unknown functionality of the file /class/edit/edit. The manipulation of the argument e_photo leads to unrestricted upload. The attack may be launched remotely. The…
AnalizadaAlta (8.8)0.51%—Oretnom23 Computer Laboratory Management System8/1/202517/6/2026
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.
AnalizadaMedia (4.3)0.77%—Oretnom23 Computer Laboratory Management System13/11/202417/6/2026
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
AnalizadaMedia (5.3)0.59%—Oretnom23 Computer Laboratory Management System30/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched…
AnalizadaMedia (5.3)0.59%—Oretnom23 Computer Laboratory Management System30/8/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.…
AnalizadaMedia (5.3)0.59%—Oretnom23 Computer Laboratory Management System30/8/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack…
AnalizadaMedia (6.5)0.60%—Oretnom23 Computer Laboratory Management System12/8/202417/6/2026
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.
ModificadaCrítica (9.8)0.60%—Oretnom23 Computer Laboratory Management System7/8/202417/6/2026
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
AnalizadaCrítica (9.8)0.70%—Oretnom23 Computer Laboratory Management System7/8/202417/6/2026
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
ModificadaMedia (5.3)9.1%—Computer Laboratory Management System Project Computer Laboratory Management System17/7/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0. Affected is an unknown function of the file /lms/classes/Master.php?f=save_record. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaMedia (6.1)0.48%—Oretnom23 Computer Laboratory Management System20/6/202417/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.
AnalizadaMedia (6.1)0.47%—Oretnom23 Computer Laboratory Management System28/5/202417/6/2026
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field.
AnalizadaMedia (6.1)0.42%—Oretnom23 Computer Laboratory Management System28/5/202417/6/2026
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.
AnalizadaMedia (6.1)0.43%—Oretnom23 Computer Laboratory Management System28/5/202417/6/2026
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
AnalizadaMedia (6.1)0.57%—Oretnom23 Computer Laboratory Management System14/5/202417/6/2026
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
AnalizadaAlta (7.3)0.87%—Oretnom23 Computer Laboratory Management System14/5/202417/6/2026
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
AnalizadaCrítica (9.4)0.61%—Oretnom23 Computer Laboratory Management System22/4/202417/6/2026
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.
AnalizadaCrítica (9.1)0.61%—Oretnom23 Computer Laboratory Management System19/4/202417/6/2026
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.
AnalizadaCrítica (9.8)0.73%—Oretnom23 Computer Laboratory Management System19/4/202417/6/2026
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.
AnalizadaMedia (5.4)0.60%—Oretnom23 Computer Laboratory Management System12/4/202417/6/2026
A vulnerability has been found in SourceCodester Computer Laboratory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.4)0.44%—Oretnom23 Computer Laboratory Management System9/4/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in /classes/Master.php?f=save_record.
AnalizadaMedia (6.1)0.63%—Oretnom23 Computer Laboratory Management System6/4/202417/6/2026
A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely.…