Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.49% | — | Mstfakts College-management-systemAI | 22/9/2026 | 23/9/2026 | A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is possible to launch the attack remotely. The exploit has been publicly disclosed… | |
| Aplazada | Baja (2.1) | 0.36% | — | Mstfakts College-management-systemAI | 6/9/2026 | 9/9/2026 | A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Mstfakts College-management-systemAI | 6/9/2026 | 10/9/2026 | A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.1) | 0.33% | — | Akpali9 Attendance-management-systemAI | 12/7/2026 | 13/7/2026 | A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date results in cross site scripting. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.4) | 0.30% | — | Cloudinary-image-management-and-manipulation-in-the-cloud-cdnAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Cloudinary Cloudinary cloudinary-image-management-and-manipulation-in-the-cloud-cdn allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cloudinary: from n/a through <= 3.3.2. | |
| Aplazada | Media (5.5) | 0.33% | — | Jackiedyh Resume-management-systemAI | 25/9/2025 | 17/6/2026 | A flaw has been found in JackieDYH Resume-management-system up to fb6b857d852dd796e748ce30c606fe5e61c18273. Affected by this issue is some unknown functionality of the file /admin/show.php. This manipulation of the argument userid causes sql injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.3) | 1.0% | — | E-solutions E-managementAI | 31/3/2025 | 17/6/2026 | Os command injection vulnerability in e-solutions e-management. This vulnerability allows an attacker to execute arbitrary commands on the server via the ‘client’ parameter in the /data/apache/e-management/api/api3.php endpoint. | |
| Aplazada | Alta (8.7) | 0.50% | — | E-solutions E-managementAI | 31/3/2025 | 17/6/2026 | Path Traversal vulnerability in e-solutions e-management. This vulnerability could allow an attacker to access confidential files outside the expected scope via the ‘file’ parameter in the /downloadReport.php endpoint. | |
| Analizada | Media (6.5) | 0.30% | — | Rpm-software-management Dnf5 | 8/5/2024 | 17/6/2026 | No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread… | |
| Modificada | Crítica (9.8) | 1.6% | — | Rpm-software-management MockFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in… |