Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
22.663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (2) | — | — | Code-projects Human Resource ManagementAI | 4/10/2026 | 4/10/2026 | A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched… | |
| Recibida | Baja (2.1) | — | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 4/10/2026 | A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component Role Attribute Handler. Such manipulation of… | |
| Recibida | Media (5.5) | — | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 4/10/2026 | A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication.… | |
| Recibida | Media (5.5) | — | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 4/10/2026 | A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument… | |
| Recibida | Baja (2.1) | — | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 4/10/2026 | A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Order Assignment Block. The manipulation of the argument order_id/delivery_person_id… | |
| Recibida | Media (5.5) | — | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 4/10/2026 | A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack… | |
| Recibida | Media (5.5) | — | — | Kishor-23 Food Waste Management SystemAI | 4/10/2026 | 4/10/2026 | A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice… | |
| Recibida | Alta (8.8) | 0.37% | — | Smart ManagerAI | 3/10/2026 | 3/10/2026 | The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (5.5) | 0.43% | — | Onetwothreeneth Hospital Management SystemAI | 2/10/2026 | 2/10/2026 | A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is an unknown function of the file php/sessions.php. The manipulation of the argument ID leads to improper authentication. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.29% | — | Onetwothreeneth Hospital Management SystemAI | 2/10/2026 | 2/10/2026 | A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Loan Management SystemAI | 2/10/2026 | 2/10/2026 | A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Media (6.5) | 0.20% | — | Avez Electronics Learning Management SystemAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Student Result Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the… | |
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | |
| Aplazada | Media (6.4) | 0.22% | — | Download ManagerAI | 2/10/2026 | 3/10/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Media (5.5) | 0.33% | — | Sourcecodester Online Reviewer Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be… | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | Samsung ManagedprovisioningAI | 2/10/2026 | 2/10/2026 | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode PET Shop Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode PET Shop Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may… | |
| Pendiente de análisis | Baja (3.7) | 0.21% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks. | |
| Pendiente de análisis | Media (4.3) | 0.16% | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | Fortra Boks ManagerAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service… |