Vulnerabilities
Summary — last 7 days
New vulnerabilities2,640▼ 268 vs. last week
Critical / high1,348▲ 90 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)58▼ 468 vs. last week
56 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.4) | 0.19% | — | Puneethreddy Event Management SystemAI | 2/26/2026 | 6/17/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and echoed back in the HTTP response without sanitization, allowing an attacker to inject and execute arbitrary JavaScript code… | |
| Analyzed | Low (2.1) | 0.48% | — | Admerc Event Management System | 2/24/2026 | 6/17/2026 | A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may be used. | |
| Analyzed | Medium (5.5) | 0.59% | — | Admerc Event Management System | 2/24/2026 | 6/17/2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analyzed | Medium (5.5) | 0.59% | — | Admerc Event Management System | 2/19/2026 | 6/17/2026 | A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analyzed | Medium (5.5) | 0.59% | — | Admerc Event Management System | 2/19/2026 | 6/17/2026 | A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The… | |
| Analyzed | Medium (5.5) | 0.59% | — | Admerc Event Management System | 2/19/2026 | 6/17/2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analyzed | Medium (5.5) | 0.34% | — | Admerc Event Management System | 2/9/2026 | 6/17/2026 | A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analyzed | Medium (6.1) | 0.23% | — | Puneethreddyhc Event Management System | 10/7/2025 | 6/17/2026 | A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System 1.0, where the event_id GET parameter is improperly handled. An attacker can craft a malicious URL to execute arbitrary JavaScript in the victim s browser by injecting code into this parameter. | |
| Analyzed | Medium (5.3) | 0.75% | — | Codezips Event Management System | 12/29/2024 | 6/17/2026 | A vulnerability, which was classified as critical, was found in Codezips Event Management System 1.0. Affected is an unknown function of the file /contact.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analyzed | Medium (5.3) | 0.55% | — | Anisha University Event Management System | 11/4/2024 | 6/17/2026 | A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file doedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analyzed | Medium (5.3) | 0.45% | — | Anisha University Event Management System | 11/4/2024 | 6/17/2026 | A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analyzed | Medium (5.3) | 0.57% | — | Anisha University Event Management System | 11/2/2024 | 6/17/2026 | A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file submit.php. The manipulation of the argument name/email/title/Year/gender/fromdate/todate/people leads to sql injection. The attack can be initiated… | |
| Analyzed | Medium (6.1) | 0.36% | — | Angeljudesuarez Event Management System | 9/5/2024 | 6/17/2026 | Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php. | |
| Analyzed | Critical (9.8) | 0.53% | — | Angeljudesuarez Event Management System | 9/5/2024 | 6/17/2026 | Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php. | |
| Analyzed | Medium (6.1) | 0.25% | — | Janobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'. | |
| Analyzed | Medium (6.1) | 0.25% | — | Janobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'. | |
| Analyzed | Medium (6.1) | 0.25% | — | Janobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'. | |
| Analyzed | Medium (6.1) | 0.25% | — | Janobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'. | |
| Analyzed | Medium (6.1) | 0.25% | — | Janobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'. | |
| Analyzed | Medium (6.1) | 0.25% | — | Janobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in… | |
| Analyzed | Medium (6.1) | 0.31% | — | Janobe School Attendence Monitoring SystemJanobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in… | |
| Analyzed | Medium (6.1) | 0.31% | — | Janobe School Attendence Monitoring SystemJanobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate', 'YearLevel', 'eventdate',… | |
| Analyzed | Medium (6.1) | 0.31% | — | Janobe School Attendence Monitoring SystemJanobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'. | |
| Analyzed | Medium (6.1) | 0.31% | — | Janobe School Attendence Monitoring SystemJanobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'. | |
| Analyzed | Medium (6.1) | 0.31% | — | Janobe School Attendence Monitoring SystemJanobe School Event Management System | 8/6/2024 | 6/17/2026 | Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in… |