Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the argument ef_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Aplazada | Baja (2.1) | 0.27% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 4/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 2/6/2026 | 22/7/2026 | A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.27% | — | Itsourcecode Fees Management SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Fees Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.25% | — | Itsourcecode Fees Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (6.5) | 0.47% | — | Oretnom23 School Fees Management System | 21/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter. | |
| Analizada | Media (6.1) | 0.48% | — | Oretnom23 School Fees Management System | 21/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | |
| Analizada | Media (6.8) | 0.57% | — | Oretnom23 School Fees Management System | 21/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | |
| Analizada | Alta (8.8) | 0.84% | — | Oretnom23 School Fees Management System | 21/3/2024 | 17/6/2026 | Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts. | |
| Analizada | Alta (7.5) | 0.74% | — | Oretnom23 School Fees Management System | 21/3/2024 | 17/6/2026 | A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. | |
| Analizada | Media (5.4) | 0.43% | — | Oretnom23 School Fees Management System | 7/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter. | |
| Analizada | Media (4.7) | 0.47% | — | Oretnom23 School Fees Management System | 7/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | |
| Analizada | Media (5.4) | 0.63% | — | School Fees Management System Project School Fees Management System1.0 | 29/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email… |