Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Code RO Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeatro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | |
| Aplazada | Media (6.5) | 0.43% | — | Codeastro Membership Management SystemAI | 7/5/2026 | 5/7/2026 | A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. | |
| Aplazada | Baja (2) | 2.1% | — | Code-projects Chamber OF Commerce Membership Management SystemAI | 29/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument mailSubject/mailMessage leads to command injection. The attack may be initiated remotely. The exploit is publicly… | |
| Modificada | Crítica (9.8) | 0.66% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | |
| Modificada | Alta (7.5) | 0.43% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). | |
| Modificada | Crítica (9.8) | 0.39% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | |
| Analizada | Baja (2) | 0.35% | — | Carmelo Intern Membership Management System | 11/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Analizada | Baja (2) | 0.38% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_activity.php. Performing a manipulation of the argument Title results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may… | |
| Analizada | Baja (2) | 0.42% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /intern/admin/delete_admin.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Baja (2) | 0.37% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /intern/admin/add_admin.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Media (5.5) | 0.44% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Analizada | Baja (2) | 0.36% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Baja (2) | 0.40% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown function of the file /intern/admin/edit_students.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (2) | 0.36% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown function of the file /intern/admin/edit_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (1.9) | 0.22% | — | Fabian Chamber OF Commerce Membership Management System | 8/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown function of the file /membership_profile.php of the component Your Info Handler. Performing manipulation of the argument Full Name/Address/City/State results in cross site scripting. The attack is… | |
| Analizada | Media (5.5) | 0.51% | — | Carmelo Intern Membership Management System | 3/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Carmelo Intern Membership Management System | 3/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Carmelo Intern Membership Management System | 2/8/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… |