Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Loan Management SystemAI | 2/10/2026 | 6/10/2026 | A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2.1) | 0.47% | — | Itsourcecode Loan Management SystemAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 31/8/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 1/10/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id. | |
| Analizada | Media (6.5) | 0.48% | — | Oretnom23 Loan Management System | 1/4/2026 | 17/6/2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive… | |
| Analizada | Media (6.5) | 0.39% | — | Oretnom23 Loan Management System | 1/4/2026 | 17/6/2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. While the frontend interface prevents users from entering negative numbers in the… | |
| Modificada | Media (6.5) | 0.39% | — | Oretnom23 Loan Management System | 31/3/2026 | 24/7/2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering negative numbers, this constraint is not… | |
| Modificada | Media (5.4) | 0.26% | — | Oretnom23 Loan Management System | 31/3/2026 | 24/7/2026 | A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a POST request, allowing an authenticated… | |
| Analizada | Baja (2.1) | 0.49% | — | Oretnom23 Loan Management System | 8/3/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be… | |
| Analizada | Media (5.5) | 0.45% | — | Angeljudesuarez Online Loan Management System | 3/11/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 3/11/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 3/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 2/11/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 2/11/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 8/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Loan Management System | 8/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 1.8% | — | Campcodes Online Loan Management System | 31/8/2025 | 17/6/2026 | A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 29/8/2025 | 17/6/2026 | A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 27/8/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_plan. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Loan Management System | 27/8/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_loan_type. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 27/8/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 27/8/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown function of the file /ajax.php?action=save_borrower. The manipulation of the argument lastname leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 27/8/2025 | 17/6/2026 | A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the file /ajax.php?action=save_payment. Executing manipulation of the argument loan_id can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Analizada | Media (6.9) | 0.80% | — | Codeastro Simple Loan Management System | 30/12/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (5) | 0.36% | — | Razormist Loan Management System | 22/10/2024 | 17/6/2026 | itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page. |