Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.25%—Os4ed OpensisclassicAI30/9/202630/9/2026
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made…
AplazadaBaja (2.1)0.20%—Os4ed Opensis-classicAI30/9/202630/9/2026
A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack…
AplazadaBaja (2)0.33%—Os4ed OpensisclassicAI30/9/20261/10/2026
A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote.…
AnalizadaMedia (5.3)0.48%—Os4ed Opensis14/7/202614/7/2026
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
AplazadaAlta (7.1)0.41%—Opensis ClassicAI11/6/202617/6/2026
openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.
ModificadaAlta (8.1)0.29%—Os4ed Opensis9/12/20255/7/2026
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.
AnalizadaAlta (8.1)0.46%—Os4ed Opensis15/7/202517/6/2026
SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php
AnalizadaCrítica (9.8)1.9%—Os4ed Opensis24/6/202517/6/2026
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.
AnalizadaAlta (7.5)0.47%—Os4ed Opensis3/4/202517/6/2026
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members.
AnalizadaCrítica (9.8)0.52%—Os4ed Opensis3/4/202517/6/2026
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.
AnalizadaCrítica (9.8)0.52%—Os4ed Opensis3/4/202517/6/2026
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.
AnalizadaCrítica (9.8)0.92%—Os4ed Opensis3/4/202517/6/2026
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
AnalizadaCrítica (9.8)0.43%—Os4ed Opensis3/4/202517/6/2026
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.
AnalizadaCrítica (9.1)0.78%—Os4ed Opensis3/4/202517/6/2026
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
AnalizadaAlta (7.5)0.46%—Os4ed Opensis2/4/202517/6/2026
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
AnalizadaAlta (8.8)0.41%—Os4ed Opensis2/4/202517/6/2026
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
AnalizadaAlta (8.8)0.87%—Os4ed Opensis2/4/202517/6/2026
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
AnalizadaCrítica (9.8)2.3%—Os4ed Opensis8/11/202417/6/2026
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.
ModificadaAlta (8.8)5.9%—Os4ed Opensis15/10/20245/7/2026
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application…
AnalizadaAlta (8.8)0.88%—Os4ed Opensis2/10/202417/6/2026
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
ModificadaAlta (8.8)0.36%—Os4ed Opensis20/11/202317/6/2026
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.
ModificadaAlta (7.5)0.88%—Os4ed Opensis20/11/202317/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
ModificadaMedia (6.1)0.63%—Os4ed Opensis20/11/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.
ModificadaMedia (6.1)0.63%—Os4ed Opensis20/11/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'include' parameter in 'ForExport.php'
ModificadaMedia (6.1)0.62%—Os4ed Opensis20/11/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of the 'calendar_id', 'school_date', 'month' or 'year' parameters in…