Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.27% | — | Ningzichun Student Management SystemAI | 25/9/2026 | 25/9/2026 | A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation of the argument reason/detail leads to cross site scripting. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2) | 0.23% | — | Ningzichun Student Management SystemAI | 25/9/2026 | 25/9/2026 | A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown functionality of the file example_lite.sql. Executing a manipulation can lead to use of default credentials. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.16% | — | Ningzichun Student Management SystemAI | 25/9/2026 | 25/9/2026 | A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project… | |
| Aplazada | Media (5.5) | 0.31% | — | Ningzichun Student Management SystemAI | 25/9/2026 | 29/9/2026 | A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown function of the file user/editLog.php. Such manipulation of the argument sid/addtime/type/reason/detail/logdate leads to authorization bypass. The attack may be… | |
| Aplazada | Media (5.5) | 0.30% | — | Ningzichun Student Management SystemAI | 24/9/2026 | 25/9/2026 | A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.38% | — | Ningzichun Student Management SystemAI | 8/9/2026 | 11/9/2026 | A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.47% | — | Ningzichun Student Management SystemAI | 8/9/2026 | 8/9/2026 | A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated… | |
| Aplazada | Media (5.5) | 0.48% | — | Ningzichun Student Management SystemAI | 8/9/2026 | 11/9/2026 | A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.25% | — | Sambitraj Student Management SystemAI | 31/8/2026 | 31/8/2026 | A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component Password Handler. Executing a manipulation of the argument Password can lead to cleartext storage of sensitive information. The attack can… | |
| Aplazada | Media (5.5) | 0.53% | — | Sambitraj Student-management-systemAI | 31/8/2026 | 31/8/2026 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Aplazada | Baja (2.9) | 0.46% | — | Sambitraj Student-management-systemAI | 31/8/2026 | 31/8/2026 | A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without 'httponly' flag. The attack may be launched remotely. A high complexity level is associated… | |
| Aplazada | Baja (2.1) | 0.35% | — | Sambitraj Student Management SystemAI | 30/8/2026 | 1/9/2026 | A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of the component Student Dashboard. The manipulation of the argument roll_no results in improper authorization. The… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sambitraj Student-management-systemAI | 23/8/2026 | 24/8/2026 | A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of the argument roll_no/name/father_name/class/mobile/email/password/remark causes sql injection. The attack is… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sambitraj Student-management-systemAI | 23/8/2026 | 27/8/2026 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. The manipulation of the argument roll_no/teacher_name results in sql injection. The attack can be executed remotely. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Imranrisal-dev Student-management-systemAI | 5/8/2026 | 12/8/2026 | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The manipulation of the argument… | |
| Aplazada | Baja (2.1) | 0.35% | — | Imranrisal-dev Student-management-systemAI | 5/8/2026 | 12/8/2026 | A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a manipulation of the argument… | |
| Aplazada | Baja (2) | 0.20% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It is possible to launch the attack… | |
| Aplazada | Baja (2.1) | 0.23% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to improper… | |
| Aplazada | Baja (2.1) | 0.27% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.33% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator Login Endpoint. Performing a manipulation of the argument a_usr/a_pwd results in sql injection. The… | |
| Aplazada | Media (5.5) | 0.33% | — | Imvks786 Student Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. The exploit is… | |
| Aplazada | Baja (2.1) | 0.21% | — | Kushan2k Student-management-systemAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The manipulation of the argument isadmin leads to… | |
| Aplazada | Baja (2.1) | 0.13% | — | Kushan2k Student Management SystemAI | 8/6/2026 | 23/7/2026 | A weakness has been identified in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this vulnerability is the function getStatus of the file controllers/GradeController.php of the component Certificate Verification Endpoint. Executing a manipulation of the argument nic can… | |
| Aplazada | Media (5.5) | 0.29% | — | Kushan2k Student-management-systemAI | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/RegisterService.php of the component Registration Endpoint. Performing a manipulation of the argument stimg results in unrestricted upload. The… | |
| Aplazada | Media (5.5) | 0.40% | — | Ealpha072 Student-management-systemAI | 3/6/2026 | 22/7/2026 | A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component Administrative Backend. Such manipulation leads to improper authentication. The attack may be… |