38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-14206
Online Student Clearance System Web
6.9
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/delete-fee.php of the component Fee Table Handler. Executing manipulation of the argument ID can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVE-2026-1422
Online Examination System Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Page. Performing a manipulation of the argument User results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

CVE-2024-8169
Online Quiz Site Web Database
6.9
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7830
Church Donation System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /reg.php. The manipulation of the argument mobile leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2026-4190
node-api-postgres Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2020-8496
Software Genérico Web
6.9
MEDIUM
EPSS
0.3%
2020 1 PoC

In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.

CVE-2026-5368
Car Rental Project Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVE-2025-10077
Online Polling System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2020-37077
Booked Scheduler Web
6.9
MEDIUM
EPSS
0.2%
2020 CWE-22 1 PoC

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.

CVE-2026-1120
KSOA Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6084
Pool of Bethesda Online Reservation System Web
6.9
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is the function uploadImage of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268825 was assigned to this vulnerability.

CVE-2025-34441
AVideo Web
6.9
MEDIUM
EPSS
47.5%
2025 CWE-359 1 PoC

AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.

CVE-2026-3765
University Management System Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A vulnerability was identified in itsourcecode University Management System 1.0. This affects an unknown function of the file /att_single_view.php. Such manipulation of the argument dt leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

CVE-2026-2158
Student Web Portal Web Database
6.9
MEDIUM
EPSS
0.1%
2026 CWE-89 1 PoC

A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely.

CVE-2021-47800
b2evolution Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. Attackers can craft a malicious HTML form to submit unauthorized changes to user profiles by tricking victims into loading a specially crafted webpage.

CVE-2026-2952
Vaelsys Web
6.9
MEDIUM
EPSS
0.3%
2026 CWE-78 1 PoC

A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request Handler. This manipulation of the argument xajaxargs causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-2087
Online Class Record System Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 2 PoCs

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVE-2026-1131
KSOA Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-3819
Men Salon Management System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12959
Portfolio Management System MCA Web Database
6.9
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /update_personal_details.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.