Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (3.6) | — | — | Mathworks SimulinkAI | 2/10/2026 | 2/10/2026 | MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution. | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 28/9/2026 | 1/10/2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available… | |
| Aplazada | Baja (2.1) | 0.30% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 28/9/2026 | 1/10/2026 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.26% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 28/9/2026 | A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting. The attack… | |
| Aplazada | Baja (2.1) | 0.28% | — | Vishalmathur Cloudclassroom-php-projectAI | 27/9/2026 | 30/9/2026 | A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 28/9/2026 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument myfid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 28/9/2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product… | |
| Aplazada | Baja (2.1) | 0.21% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 30/9/2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit is now public and may be used. This product does… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 26/9/2026 | 28/9/2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now… | |
| Aplazada | Media (5.5) | 0.39% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 26/9/2026 | 30/9/2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid results in sql injection. The attack can be launched remotely. The exploit is now public and… | |
| Aplazada | Media (5.5) | 0.39% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 26/9/2026 | 28/9/2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromstudent.php. The manipulation of the argument eno leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.42% | — | Vishalmathur Cloudclassroom-php-projectAI | 26/9/2026 | 28/9/2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a manipulation of the argument queryx can lead to cross site scripting. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.19% | — | Vishalmathur Cloudclassroom-php-projectAI | 26/9/2026 | 30/9/2026 | A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the… | |
| Aplazada | Baja (2) | 0.19% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 26/9/2026 | 28/9/2026 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file managevideos2.php of the component Faculty Video Management. Such manipulation of the argument V_Title/V_Url/V_Remarks leads to cross site… | |
| Aplazada | Baja (2.1) | 0.30% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 25/9/2026 | 29/9/2026 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation of the argument editassid leads to sql injection. The attack may be launched remotely.… | |
| Aplazada | Media (5.5) | 0.26% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 25/9/2026 | 28/9/2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.19% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 25/9/2026 | 28/9/2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestudent.php of the component Student Update Functionality. The manipulation of the argument eno results in sql injection. The attack can be launched… | |
| Aplazada | Media (5.5) | 0.31% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 25/9/2026 | 28/9/2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. The manipulation of the argument gid leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.51% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 25/9/2026 | 29/9/2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authentication. Executing a manipulation of the argument fid/pass can lead to sql injection. It… | |
| Aplazada | Media (4.9) | 0.33% | — | Rankmath Rank Math SEOAI | 2/9/2026 | 3/9/2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users. | |
| Aplazada | Baja (2.7) | 0.28% | — | Rankmath Rank Math SEOAI | 2/9/2026 | 3/9/2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the… | |
| Aplazada | Baja (2.7) | 0.30% | — | Rankmath Rank Math SEOAI | 2/9/2026 | 3/9/2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts. | |
| Aplazada | Baja (2.7) | 0.28% | — | Rankmath Rank Math SEOAI | 2/9/2026 | 3/9/2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other… | |
| Aplazada | Baja (3.7) | 0.26% | — | Rankmath Rank Math SEOAI | 2/9/2026 | 3/9/2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts. |