Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.54%—Soarkey StudentmanagementAI14/9/202614/9/2026
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management.…
AplazadaMedia (5.5)0.52%—Soarkey StudentmanagementAI31/8/202631/8/2026
A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component Administrative Servlet. Executing a manipulation of the argument action can lead to authorization…
AplazadaBaja (2.1)0.33%—Soarkey StudentmanagementAISoarkey XueshengxinxiguanlixitongAI31/8/20261/9/2026
A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a manipulation of the argument cno results in sql injection. It is possible to initiate…
AplazadaBaja (2.1)0.45%—Hemant6488 Codeigniter StudentmanagementsystemAI26/5/202623/7/2026
A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carried out remotely.…
AplazadaMedia (5.5)0.47%—Hemant6488 Codeigniter-studentmanagementsystemAI26/5/202623/7/2026
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely.…
AplazadaMedia (5.5)0.41%—Yashpokharna2555 StudentmanagementsystemAI25/5/202623/7/2026
A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has…
AplazadaBaja (2)0.33%—Yashpokharna2555 StudentmanagementsystemAI25/5/202623/7/2026
A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file /student.php. Performing a manipulation of the argument FIRST_NAME results in cross site scripting. The attack can be initiated remotely. The exploit is now…
AplazadaMedia (5.5)0.41%—Yashpokharna2555 StudentmanagementsystemAI25/5/202623/7/2026
A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.php. Such manipulation of the argument FIRST_NAME/Last_Name/EMAIL leads to sql injection. It is possible to launch the…
AplazadaMedia (5.5)0.41%—Yashpokharna2555 StudentmanagementsystemAI25/5/202623/7/2026
A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown function of the file /success.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaBaja (1.9)0.23%—Zerowdd Studentmanager9/2/202617/6/2026
A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross site scripting. The…
ModificadaMedia (4.8)0.19%—Daycloud Studentmanage18/7/20255/7/2026
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.
ModificadaMedia (4.8)0.19%—Daycloud Studentmanage18/7/20255/7/2026
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.
ModificadaMedia (4.8)0.19%—Daycloud Studentmanage18/7/20255/7/2026
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.
ModificadaAlta (8.8)0.34%—Daycloud Studentmanage18/7/20255/7/2026
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.
ModificadaMedia (6.5)0.16%—Daycloud Studentmanage18/7/20255/7/2026
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
AnalizadaMedia (5.3)0.51%—Zerowdd Studentmanager14/4/202517/6/2026
A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherList. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.1)0.59%—Huanfenz Studentmanager14/4/202517/6/2026
A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated…
AnalizadaMedia (5.3)0.49%—Huanfenz Studentmanager14/4/202517/6/2026
A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0. This affects an unknown part of the component Teacher String Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaMedia (6.9)0.36%—Daycloud StudentmanageAI16/3/202517/6/2026
A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. The manipulation of the argument query leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
AnalizadaMedia (5.1)0.29%—Zerowdd Studentmanager6/1/202517/6/2026
A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the function submitAddPermission of the file src/main/java/com/zero/system/controller/PermissionController. java. The manipulation of the argument url leads to cross site scripting. The attack may be initiated…
AnalizadaMedia (5.1)0.43%—Zerowdd Studentmanager5/1/202517/6/2026
A vulnerability was found in ZeroWdd studentmanager 1.0. It has been declared as problematic. This vulnerability affects the function submitAddRole of the file src/main/java/com/zero/system/controller/RoleController. java. The manipulation of the argument name leads to cross site scripting. The attack can be initiated…
AnalizadaMedia (5.3)0.38%—Zerowdd Studentmanager5/1/202517/6/2026
A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function addTeacher/editTeacher of the file src/main/Java/com/wdd/studentmanager/controller/TeacherController. java. The manipulation of the argument file leads to unrestricted upload. It is possible to launch…
AnalizadaMedia (5.3)0.36%—Zerowdd Studentmanager5/1/202517/6/2026
A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. The manipulation of the argument file leads to unrestricted upload. The attack may…
ModificadaMedia (5.4)0.48%—Zerowdd Studentmanager21/8/202317/6/2026
Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code via the username parameter in the student list function.