Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.50% | — | Itsourcecode Online Student Enrollment System | 10/4/2026 | 17/6/2026 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. | |
| Analizada | Crítica (9.8) | 0.50% | — | Itsourcecode Online Student Enrollment System | 10/4/2026 | 17/6/2026 | itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Itsourcecode Online Student Enrollment System | 10/4/2026 | 17/6/2026 | A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropriate cleaning or… | |
| Analizada | Crítica (9.8) | 0.50% | — | Itsourcecode Online Student Enrollment System | 10/4/2026 | 17/6/2026 | A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation. | |
| Modificada | Media (5.5) | 0.47% | — | Campcodes Online Student Enrollment System | 12/12/2025 | 17/6/2026 | A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
| Modificada | Baja (2) | 0.38% | — | Campcodes Online Student Enrollment System | 12/12/2025 | 17/6/2026 | A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=user-profile. Performing a manipulation of the argument userphoto results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be… | |
| Analizada | Media (5.3) | 0.62% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Online Student Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file instructorSubjects.php. The manipulation of the argument instructorId leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file newfaculty.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file listofinstructor.php. The manipulation of the argument FullName leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file newDept.php. The manipulation of the argument deptname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.55% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file listofcourse.php. The manipulation of the argument idno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file editSubject.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.62% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file listofsubject.php. The manipulation of the argument subjcode leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Online Student Enrollment System | 27/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file listofstudent.php. The manipulation of the argument lname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 14% | — | Online Student Enrollment System Project Online Student Enrollment System | 13/1/2023 | 17/6/2026 | Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php. | |
| Modificada | Media (5.4) | 0.40% | — | Online Student Enrollment System Project Online Student Enrollment System | 12/1/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /admin/register.php of Online Student Enrollment System v1.0 allows attackers to execute arbitrary web scripts via a crafted payload injected into the name parameter. |