Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2604▼ 298 respecto a la semana anterior
Críticas / altas1343▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.71% | — | Walterjnr1 Web-based Student Clearance System | 29/2/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-admin.php of the component Edit User Profile Page. The manipulation of the argument Fullname leads to sql injection.… | |
| Analizada | Crítica (9.8) | 0.76% | — | Walterjnr1 Web-based Student Clearance System | 29/2/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin/login.php. The manipulation of the argument txtpassword leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Media (4.8) | 0.49% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 28/11/2022 | 17/6/2026 | Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 28/11/2022 | 17/6/2026 | Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter. | |
| Modificada | Media (4.8) | 0.48% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 28/11/2022 | 17/6/2026 | Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter. | |
| Modificada | Media (4.8) | 0.48% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 1/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /admin/add-fee.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter. | |
| Modificada | Media (4.8) | 0.48% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 1/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /admin/edit-admin.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtemail parameter. | |
| Modificada | Alta (8.8) | 0.58% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 28/10/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This affects an unknown part of the file Admin/edit-admin.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.54% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 9/10/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The… | |
| Modificada | Media (5.4) | 0.66% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 8/10/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affected by this issue is the function prepare of the file /Admin/add-student.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.68% | — | Web-based Student Clearance System Project Web-based Student Clearance System | 7/10/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of the argument txtusername leads to sql injection. It is possible to launch the… |