Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.33%—Itsourcecode Information System Society Membership SystemAI7/9/202628/9/2026
A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit…
AplazadaMedia (5.5)0.41%—Code-projects Student Membership SystemAI31/3/202624/7/2026
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The exploit has…
AplazadaBaja (2.1)0.32%—Code-projects Student Membership SystemAI31/3/202617/6/2026
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.32%—Code-projects Student Membership SystemAI31/3/202617/6/2026
A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
AplazadaMedia (6.9)0.41%—Code-projects Student Membership SystemAI31/3/202617/6/2026
A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the component User Registration Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely.
AnalizadaAlta (8.8)0.33%—Lopalopa Live Membership System12/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
AnalizadaAlta (7.6)1.1%—Lopalopa Live Membership System12/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.
AnalizadaCrítica (9.8)1.0%—Lopalopa Live Membership System12/8/202417/6/2026
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.
AnalizadaCrítica (9.8)1.2%—Lopalopa Live Membership System12/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
ModificadaCrítica (9.8)0.82%—Razormist Simple Membership System29/9/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaAlta (7.5)0.61%—Razormist Simple Membership System17/9/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.61%—Razormist Simple Membership System9/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been rated as critical. This issue affects some unknown processing of the file delete_member.php. The manipulation of the argument mem_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.74%—Razormist Simple Membership System9/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.60%—Razormist Simple Membership System8/9/202317/6/2026
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been classified as critical. This affects an unknown part of the file club_edit_query.php. The manipulation of the argument club_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)1.3%—Simple Membership System Using PHP AND Ajax Project Simple Membership System Using PHP AND Ajax24/1/202217/6/2026
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.
ModificadaAlta (7.5)0.97%💥 ExploitDevelop IT Easy Membership System13/11/200816/6/2026
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_login.php and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained…
ModificadaAlta (7.5)2.8%💥 ExploitAgtc Websolutions Php-agtc Membership System31/10/200716/6/2026
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.
ModificadaMedia (4.9)1.1%—Agtc Websolutions Php-agtc Membership System31/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).
Orbitaley — Vulnerabilidades