Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects GYM Management System IN PHPAIMicrosoft Windows NTAI | 4/5/2026 | 17/6/2026 | A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects GYM Management SystemAI | 1/5/2026 | 17/6/2026 | A vulnerability was found in code-projects Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_exercises.php. The manipulation of the argument edit_exercise results in sql injection. It is possible to launch the attack remotely. The exploit has been made public… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Simple GYM Management SystemAI | 31/3/2026 | 24/7/2026 | A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql injection. Remote exploitation of the attack is… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Simple GYM Management SystemAI | 22/3/2026 | 17/6/2026 | A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Crítica (9.8) | 0.52% | — | Carmelo Simple GYM Management System | 2/3/2026 | 17/6/2026 | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. | |
| Analizada | Baja (3.5) | 0.14% | — | Phpgurukul GYM Management System | 17/2/2026 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint. | |
| Analizada | Crítica (9.4) | 0.63% | — | Abhishekmali21 GYM Management System | 12/1/2026 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issues to inject… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Amansuryawanshi GYM Management System PHPAI | 12/1/2026 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (3) change_s_pwd.php.… | |
| Modificada | Baja (2.1) | 0.29% | — | Codeastro GYM Management System | 14/11/2025 | 17/6/2026 | A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used… | |
| Modificada | Baja (2) | 0.40% | — | Codeastro GYM Management System | 3/11/2025 | 17/6/2026 | A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Modificada | Baja (2) | 0.37% | — | Codeastro GYM Management System | 3/11/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation of the argument id/ini_weight results in sql injection. The attack may be initiated remotely. The exploit has been made public and… | |
| Modificada | Baja (2.1) | 0.45% | — | Codeastro GYM Management System | 27/10/2025 | 30/9/2026 | A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/actions/remove-announcement.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.33% | — | Codeastro GYM Management System | 27/10/2025 | 17/6/2026 | A vulnerability has been found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/actions/check-attendance.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 0.34% | — | Codeastro GYM Management System | 11/10/2025 | 17/6/2026 | A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.38% | — | Codeastro GYM Management System | 11/10/2025 | 17/6/2026 | A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 0.34% | — | Codeastro GYM Management System | 11/10/2025 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly… | |
| Modificada | Baja (2.1) | 0.34% | — | Codeastro GYM Management System | 11/10/2025 | 17/6/2026 | A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made… | |
| Modificada | Baja (2.1) | 0.38% | — | Codeastro GYM Management System | 10/10/2025 | 17/6/2026 | A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of the argument plan results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may… | |
| Analizada | Baja (2.1) | 0.34% | — | Codeastro GYM Management System | 10/10/2025 | 17/6/2026 | A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Alta (8.8) | 0.45% | — | Projectworlds GYM Management System | 8/10/2025 | 17/6/2026 | ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes GYM Management System | 23/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Gym Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may… | |
| Analizada | Baja (2.1) | 0.26% | — | Oretnom23 GYM Management System | 22/6/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.59% | — | Admerc GYM Management System | 9/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_package. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.59% | — | Admerc GYM Management System | 9/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.59% | — | Admerc GYM Management System | 9/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_plan. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… |