Vulnerabilidades en itsourcecode

661 resultados
Análisis Vexday

Com 539 CVEs catalogadas e 58 surgidas nos últimos 90 dias, o volume de vulnerabilidades associadas a produtos do itsourcecode apresenta uma cadência de descoberta elevada e recente que merece acompanhamento contínuo. Nenhuma entrada consta no catálogo KEV da CISA — taxa abaixo da média geral —, e os scores EPSS registrados permanecem baixos, incluindo o da CVE-2025-0944, apontada como a mais crítica no momento, com EPSS de 0,0096. Apesar da ausência de exploração ativa confirmada, a presença de 59 CVEs com PoC pública amplia a superfície de risco potencial, já que provas de conceito facilitam a conversão de vulnerabilidades teóricas em ataques reais. O predomínio de CWE-89 (SQL Injection) como tipo de falha mais recorrente indica deficiências sistemáticas na camada de acesso a dados, sugerindo que revisões de código centradas em sanitização de entrada e uso de consultas parametrizadas devem ser priorizadas.

CVE-2025-10592MEDIUMitsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injectionEPSS 0.4%CVE-2025-7125MEDIUMitsourcecode Employee Management System editempeducation.php sql injectionEPSS 0.4%CVE-2025-11054MEDIUMitsourcecode Open Source Job Portal index.php sql injectionEPSS 0.4%CVE-2025-7126MEDIUMitsourcecode Employee Management System adminprofile.php sql injectionEPSS 0.4%CVE-2026-4014MEDIUMitsourcecode Cafe Reservation System Registration signup.php sql injectionEPSS 0.4%CVE-2025-15353MEDIUMitsourcecode Society Management System edit_admin_query.php edit_admin_query sql injectionEPSS 0.4%CVE-2026-3152MEDIUMitsourcecode College Management System teacher-salary.php sql injectionEPSS 0.4%CVE-2025-12607MEDIUMitsourcecode Online Loan Management System manage_payment.php sql injectionEPSS 0.4%CVE-2025-15354MEDIUMitsourcecode Society Management System add_admin.php sql injectionEPSS 0.4%CVE-2026-3980MEDIUMitsourcecode Online Doctor Appointment System patient_action.php sql injectionEPSS 0.4%CVE-2026-3981MEDIUMitsourcecode Online Doctor Appointment System doctor_action.php sql injectionEPSS 0.4%CVE-2026-0544MEDIUMitsourcecode School Management System index.php sql injectionEPSS 0.4%CVE-2026-1176MEDIUMitsourcecode School Management System index.php sql injectionEPSS 0.4%CVE-2025-6610MEDIUMitsourcecode Employee Management System editempprofile.php sql injectionEPSS 0.4%CVE-2025-15168MEDIUMitsourcecode Student Management System statistical.php sql injectionEPSS 0.4%CVE-2025-13485MEDIUMitsourcecode Online File Management System ajax.php sql injectionEPSS 0.4%CVE-2025-15165MEDIUMitsourcecode Online Cake Ordering System updatecustomer.php sql injectionEPSS 0.4%CVE-2025-15166MEDIUMitsourcecode Online Cake Ordering System updatesupplier.php sql injectionEPSS 0.4%CVE-2026-3164MEDIUMitsourcecode News Portal Project contactus.php sql injectionEPSS 0.4%CVE-2026-5334MEDIUMitsourcecode Online Enrollment System Parameter index.php sql injectionEPSS 0.4%