Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.45%—Phpgurukul Beauty Parlour Management System14/9/202517/6/2026
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.5)0.41%—Phpgurukul Beauty Parlour Management System14/9/202517/6/2026
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/readenq.php. Executing manipulation of the argument delid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.44%💥 PoCPhpgurukul Beauty Parlour Management System4/9/202517/6/2026
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.5)0.44%—Phpgurukul Beauty Parlour Management System4/9/202517/6/2026
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.44%—1000projects Beauty Parlour Management System4/9/202517/6/2026
A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may…
AnalizadaMedia (5.5)0.44%—1000projects Beauty Parlour Management System3/9/202517/6/2026
A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly…
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public…
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of the argument sids[] results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.45%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be…
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and…
AplazadaCrítica (9.8)0.41%—Manfcarlo WP Funnel ManagerAI28/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection.This issue affects WP Funnel Manager: from n/a through <= 1.4.0.
AnalizadaMedia (5.5)0.40%—Phpgurukul Beauty Parlour Management System15/8/202517/6/2026
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appointment.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public…
AplazadaAlta (8.1)0.65%—Frenify ArloAI9/6/202517/6/2026
Path Traversal: '.../...//' vulnerability in Frenify Arlo arlo allows PHP Local File Inclusion.This issue affects Arlo: from n/a through <= 6.0.3.
AplazadaMedia (4.3)0.14%—Juan Carlos WP Mapa Politico SpainAI19/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Juan Carlos WP Mapa Politico España wp-mapa-politico-spain allows Cross Site Request Forgery.This issue affects WP Mapa Politico España: from n/a through <= 3.8.0.
AnalizadaMedia (6.9)0.58%—Phpgurukul Beauty Parlour Management System18/5/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.51%—Phpgurukul Beauty Parlour Management System16/5/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.51%—Phpgurukul Beauty Parlour Management System16/5/202517/6/2026
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
AplazadaMedia (5.3)0.33%—Carlo LA Pera WP Customize Login PageAI24/4/202517/6/2026
Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Customize Login Page: from n/a through <= 1.6.5.
AplazadaMedia (5.9)0.27%—Carlo LA Pera WP Customize Login PageAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Stored XSS.This issue affects WP Customize Login Page: from n/a through <= 1.6.5.
ModificadaAlta (8.8)0.19%—Carlosminatti Delete Original Image11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This issue affects Delete Original Image: from n/a through <= 0.4.
AnalizadaMedia (5.9)0.34%—Darkseid Beauty Parlour Management System14/2/202517/6/2026
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.
AplazadaAlta (7.1)0.20%—Cybio GravatarlocalcacheAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request Forgery.This issue affects GravatarLocalCache: from n/a through <= 1.1.2.
AnalizadaMedia (5.3)0.65%—1000projects Beauty Parlour Management System31/12/202417/6/2026
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-customer-services.php of the component Customer Detail Handler. The manipulation of the argument sids[] leads to sql injection. The…
ModificadaMedia (6.1)0.50%—Phpgurukul Beauty Parlour Management System10/12/20245/7/2026
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
ModificadaCrítica (9.8)0.62%—Phpgurukul Beauty Parlour Management System10/12/20245/7/2026
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
Orbitaley — Vulnerabilidades