Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.50% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through… | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Analizada | Baja (2.1) | 0.32% | — | Oretnom23 Computer Laboratory Management System | 8/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The manipulation results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and… | |
| Analizada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /settings/controller.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Modificada | Media (5.5) | 0.41% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.48% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/9/2025 | 25/9/2026 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Alta (8.8) | 0.49% | — | Oretnom23 Computer Laboratory Management System | 29/4/2025 | 17/6/2026 | A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter | |
| Analizada | Media (5.3) | 0.38% | — | Campcodes Computer Laboratory Management System | 9/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0. This affects an unknown part of the file /class/edit/edit. The manipulation of the argument s_lname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.47% | — | Campcodes Computer Laboratory Management System | 9/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is some unknown functionality of the file /class/edit/edit. The manipulation of the argument e_photo leads to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Alta (8.8) | 0.51% | — | Oretnom23 Computer Laboratory Management System | 8/1/2025 | 17/6/2026 | SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list. | |
| Analizada | Media (4.3) | 0.77% | — | Oretnom23 Computer Laboratory Management System | 13/11/2024 | 17/6/2026 | SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php | |
| Analizada | Media (5.3) | 0.59% | — | Oretnom23 Computer Laboratory Management System | 30/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched… | |
| Analizada | Media (5.3) | 0.59% | — | Oretnom23 Computer Laboratory Management System | 30/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.59% | — | Oretnom23 Computer Laboratory Management System | 30/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (6.5) | 0.60% | — | Oretnom23 Computer Laboratory Management System | 12/8/2024 | 17/6/2026 | Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories. | |
| Modificada | Crítica (9.8) | 0.60% | — | Oretnom23 Computer Laboratory Management System | 7/8/2024 | 17/6/2026 | SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection. | |
| Analizada | Crítica (9.8) | 0.70% | — | Oretnom23 Computer Laboratory Management System | 7/8/2024 | 17/6/2026 | SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection. | |
| Modificada | Media (5.3) | 9.1% | — | Computer Laboratory Management System Project Computer Laboratory Management System | 17/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0. Affected is an unknown function of the file /lms/classes/Master.php?f=save_record. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (6.1) | 0.48% | — | Oretnom23 Computer Laboratory Management System | 20/6/2024 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters. | |
| Analizada | Media (6.1) | 0.47% | — | Oretnom23 Computer Laboratory Management System | 28/5/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field. |