Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.36% | — | Code-projects Task Management SystemAI | 6/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management System IN PHPAI | 6/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management SystemAI | 18/8/2026 | 20/8/2026 | A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Task Management SystemAI | 10/8/2026 | 12/8/2026 | A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in cross site scripting. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.55% | — | Code-projects Task Management SystemAI | 9/8/2026 | 14/8/2026 | A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management SystemAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management SystemAI | 9/8/2026 | 12/8/2026 | A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.67% | — | Code-projects Task Management SystemAI | 9/8/2026 | 12/8/2026 | A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public… | |
| Analizada | Baja (2) | 0.49% | — | Oretnom23 Employee Task Management System | 8/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2) | 0.49% | — | Oretnom23 Employee Task Management System | 8/3/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of the file /daily-attendance-report.php of the component GET Parameter Handler. The manipulation of the argument Date results in sql injection. The attack may be performed from remote. The exploit is… | |
| Analizada | Media (6.9) | 0.60% | — | 1000projects Employee Task Management System | 30/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.52% | — | 1000projects Employee Task Management System | 30/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/AdminLogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.67% | — | Oretnom23 Employee Task Management System | 25/4/2024 | 17/6/2026 | Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php. | |
| Modificada | Crítica (9.8) | 0.63% | — | Mayurik PHP Task Management System | 24/4/2024 | 17/6/2026 | SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component. | |
| Analizada | Crítica (9.8) | 1.2% | — | Mayurik PHP Task Management System | 15/4/2024 | 17/6/2026 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Mayurik PHP Task Management System | 15/4/2024 | 17/6/2026 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php. | |
| Analizada | Media (6.5) | 0.57% | — | Mayurik PHP Task Management System | 3/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit-task.php. The manipulation of the argument task_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Alta (8.8) | 0.71% | — | Mayurik PHP Task Management System | 3/4/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.67% | — | Mayurik PHP Task Management System | 3/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester PHP Task Management System 1.0. Affected is an unknown function of the file admin-manage-user.php. The manipulation of the argument admin_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.67% | — | Mayurik PHP Task Management System | 3/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester PHP Task Management System 1.0. This issue affects some unknown processing of the file admin-password-change.php. The manipulation of the argument admin_id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Alta (8.8) | 0.67% | — | Mayurik PHP Task Management System | 3/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester PHP Task Management System 1.0. This vulnerability affects unknown code of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 0.93% | — | Mayurik PHP Task Management System | 26/3/2024 | 17/6/2026 | The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection | |
| Analizada | Alta (7.5) | 0.79% | — | Mayurik PHP Task Management System | 26/3/2024 | 17/6/2026 | SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php. | |
| Analizada | Alta (7.5) | 0.85% | — | Mayurik PHP Task Management System | 26/3/2024 | 17/6/2026 | SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id= | |
| Analizada | Crítica (9.8) | 0.67% | — | Oretnom23 Employee Task Management System | 18/3/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to authorization bypass. The attack can be initiated remotely. The exploit has been… |