Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.21% | — | Codeastro Student Attendance Management SystemAI | 13/6/2026 | 23/7/2026 | A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.27% | — | Codeastro Student Attendance Management SystemAI | 8/6/2026 | 23/7/2026 | A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be… | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters. | |
| Analizada | Alta (8.8) | 0.30% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters. | |
| Analizada | Media (6.1) | 0.20% | — | Student Attendance Management System Project Student Attendance Management System | 7/8/2025 | 17/6/2026 | Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php. | |
| Analizada | Media (5.3) | 0.64% | — | Oretnom23 School Intramurals - Student Attendance Management System | 26/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_sy.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 School Intramurals - Student Attendance Management System | 16/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 School Intramurals - Student Attendance Management System | 16/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Media (4.8) | 0.46% | — | Student Attendance Management System Project Student Attendance Management System | 17/11/2022 | 17/6/2026 | A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.2) | 0.56% | — | Student Attendance Management System Project Student Attendance Management System | 17/11/2022 | 17/6/2026 | A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.55% | — | Student Attendance Management System Project Student Attendance Management System | 29/3/2022 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via the couse filed in index.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Student Attendance Management System Project Student Attendance Management System | 29/3/2022 | 17/6/2026 | A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality. |