Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester CAR Driving School Management SystemAI | 30/9/2026 | 2/10/2026 | A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode School Management SystemAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.5) | 0.55% | — | School Management Education Learning ERPAI | 16/8/2026 | 20/8/2026 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (5.3) | 0.22% | — | Weblizar School ManagementAI | 17/6/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions. | |
| Aplazada | Media (6.9) | 0.42% | — | Projectsandprograms School Management SystemAI | 3/6/2026 | 22/7/2026 | ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The application does not require or prompt users to change the password upon first login. This behavior allows attackers to… | |
| Aplazada | Media (5.1) | 0.49% | — | Projectsandprograms School-management-systemAI | 3/6/2026 | 22/7/2026 | ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other users’ browsers. Critically, when… | |
| Aplazada | Alta (8.8) | 0.23% | — | Mojoomla School ManagementAI | 3/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Alta (7.6) | 0.23% | — | Mojoomla School ManagementAI | 3/6/2026 | 22/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Advanced School Management SystemAI | 1/5/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commonController.php of the component checkEmail Endpoint. This manipulation causes sql injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Media (6.1) | 0.44% | — | Mahmoudai1 School Management SystemAI | 28/4/2026 | 20/7/2026 | A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php. | |
| Aplazada | Media (5.5) | 0.41% | — | Projectsandprograms School Management SystemAI | 20/4/2026 | 17/6/2026 | A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of the component HTTP GET Parameter Handler. The manipulation of the argument bus_id leads to sql injection. It is possible… | |
| Aplazada | Media (6.1) | 0.18% | — | Manikandan580 School Management SystemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter. | |
| Aplazada | Crítica (9.8) | 0.29% | — | Manikandan580 School-management-systemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter. | |
| Aplazada | Media (6.1) | 0.18% | — | Manikandan580 School-management-systemAI | 14/4/2026 | 17/6/2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms/admin/contact-us.php via the email POST parameter. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Manikandan580 School Management SystemAI | 14/4/2026 | 17/6/2026 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information. | |
| Aplazada | Baja (2.1) | 0.35% | — | Projectsandprograms School Management SystemAI | 3/4/2026 | 24/7/2026 | A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handler. This manipulation of the argument File causes unrestricted upload. Remote… | |
| Aplazada | Media (5.1) | 0.32% | — | Qdocs Smart School Management SystemAI | 27/3/2026 | 17/6/2026 | A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out… | |
| Analizada | Alta (7.1) | 0.50% | — | Wecodex School Management System CMS | 26/3/2026 | 17/6/2026 | School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to the processlogin… | |
| Analizada | Media (5.5) | 0.59% | — | Itsourcecode School Management System | 26/2/2026 | 17/6/2026 | A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.40% | — | Itsourcecode School Management System | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used… | |
| Analizada | Media (5.5) | 0.40% | — | Itsourcecode School Management System | 8/2/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/report/index.php. The manipulation of the argument ay leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.34% | — | Itsourcecode School Management System | 7/2/2026 | 17/6/2026 | A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.35% | — | Itsourcecode School Management System | 6/2/2026 | 17/6/2026 | A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.44% | — | Itsourcecode School Management System | 6/2/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.44% | — | Itsourcecode School Management System | 6/2/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. |