Vulnerabilities in itsourcecode

661 results
Vexday analysis

Com 539 CVEs catalogadas e 58 surgidas nos últimos 90 dias, o volume de vulnerabilidades associadas a produtos do itsourcecode apresenta uma cadência de descoberta elevada e recente que merece acompanhamento contínuo. Nenhuma entrada consta no catálogo KEV da CISA — taxa abaixo da média geral —, e os scores EPSS registrados permanecem baixos, incluindo o da CVE-2025-0944, apontada como a mais crítica no momento, com EPSS de 0,0096. Apesar da ausência de exploração ativa confirmada, a presença de 59 CVEs com PoC pública amplia a superfície de risco potencial, já que provas de conceito facilitam a conversão de vulnerabilidades teóricas em ataques reais. O predomínio de CWE-89 (SQL Injection) como tipo de falha mais recorrente indica deficiências sistemáticas na camada de acesso a dados, sugerindo que revisões de código centradas em sanitização de entrada e uso de consultas parametrizadas devem ser priorizadas.

CVE-2025-9472MEDIUMitsourcecode Apartment Management System add_owner_utility.php sql injectionEPSS 0.4%CVE-2025-9511MEDIUMitsourcecode Apartment Management System addvisitor.php sql injectionEPSS 0.4%CVE-2025-9601MEDIUMitsourcecode Apartment Management System employee_salary_setup.php sql injectionEPSS 0.4%CVE-2025-9509MEDIUMitsourcecode Apartment Management System fair_info_all.php sql injectionEPSS 0.4%CVE-2025-9596MEDIUMitsourcecode Sports Management System login.php sql injectionEPSS 0.4%CVE-2025-10670MEDIUMitsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile.php sql injectionEPSS 0.4%CVE-2025-9510MEDIUMitsourcecode Apartment Management System addbranch.php sql injectionEPSS 0.4%CVE-2025-11434MEDIUMitsourcecode Student Transcript Processing System login.php sql injectionEPSS 0.4%CVE-2025-9594MEDIUMitsourcecode Apartment Management System complain_info.php sql injectionEPSS 0.4%CVE-2025-8972MEDIUMitsourcecode Online Tour and Travel Management System page-login.php sql injectionEPSS 0.4%CVE-2025-8968MEDIUMitsourcecode Online Tour and Travel Management System disapprove_user.php sql injectionEPSS 0.4%CVE-2025-8967MEDIUMitsourcecode Online Tour and Travel Management System packages.php sql injectionEPSS 0.4%CVE-2025-9837MEDIUMitsourcecode Student Information Management System index.php sql injectionEPSS 0.4%CVE-2025-9155MEDIUMitsourcecode Online Tour and Travel Management System forget_password.php sql injectionEPSS 0.4%CVE-2025-10062MEDIUMitsourcecode Student Information Management System login.php sql injectionEPSS 0.4%CVE-2025-8925MEDIUMitsourcecode Sports Management System match.php sql injectionEPSS 0.4%CVE-2025-9792MEDIUMitsourcecode Apartment Management System e_all_info.php sql injectionEPSS 0.4%CVE-2025-9643MEDIUMitsourcecode Apartment Management System utility_bill_setup.php sql injectionEPSS 0.4%CVE-2025-11101MEDIUMitsourcecode Open Source Job Portal index.php sql injectionEPSS 0.4%CVE-2025-9793MEDIUMitsourcecode Apartment Management System Setting admin.php sql injectionEPSS 0.4%