Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.56% | — | Sunnygkp10 Online-exam-system- | 30/1/2026 | 17/6/2026 | Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information. | |
| Analizada | Alta (8.8) | 0.41% | — | Sunnygkp10 Online-exam-system- | 30/1/2026 | 17/6/2026 | Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters. | |
| Analizada | Crítica (9.1) | 0.40% | — | Jayesh Online Exam System | 12/1/2026 | 17/6/2026 | A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request. | |
| Analizada | Crítica (9.8) | 0.49% | — | Nayem-howlader Online Exam System | 28/3/2025 | 17/6/2026 | Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php. | |
| Aplazada | Media (6.1) | 0.33% | — | Sunnygkp10 Online Exam SystemAI | 17/1/2025 | 5/7/2026 | Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter. | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 Online Exam System | 25/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.53% | — | Jayesh Online Exam System | 12/8/2024 | 17/6/2026 | A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access. | |
| Analizada | Alta (8.1) | 0.80% | — | Jayesh Online Exam System | 12/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Jayesh Online Exam System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code via "rname" and "email" parameter fields | |
| Modificada | Alta (8.8) | 0.73% | — | Online Exam System Project Online Exam System | 17/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Exam System 1.0. This issue affects some unknown processing of the file /jurusanmatkul/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.73% | — | Online Exam System Project Online Exam System | 17/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Exam System 1.0. This vulnerability affects unknown code of the file /kelasdosen/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /jurusan/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /matkul/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /kelas/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been classified as critical. This affects an unknown part of the file /dosen/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mahasiswa/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.73% | — | Online Exam System Project Online Exam System | 11/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. This affects an unknown part of the file adminpanel/admin/facebox_modal/updateCourse.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the… |