Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.45% | — | Phpgurukul Beauty Parlour Management System | 14/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Beauty Parlour Management System | 14/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/readenq.php. Executing manipulation of the argument delid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.44% | 💥 PoC | Phpgurukul Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.44% | — | Phpgurukul Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Beauty Parlour Management System | 3/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of the argument sids[] results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.45% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Manfcarlo WP Funnel ManagerAI | 28/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection.This issue affects WP Funnel Manager: from n/a through <= 1.4.0. | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Beauty Parlour Management System | 15/8/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appointment.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.1) | 0.65% | — | Frenify ArloAI | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Frenify Arlo arlo allows PHP Local File Inclusion.This issue affects Arlo: from n/a through <= 6.0.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Juan Carlos WP Mapa Politico SpainAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Juan Carlos WP Mapa Politico España wp-mapa-politico-spain allows Cross Site Request Forgery.This issue affects WP Mapa Politico España: from n/a through <= 3.8.0. | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul Beauty Parlour Management System | 18/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Beauty Parlour Management System | 16/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Beauty Parlour Management System | 16/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.3) | 0.33% | — | Carlo LA Pera WP Customize Login PageAI | 24/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Customize Login Page: from n/a through <= 1.6.5. | |
| Aplazada | Media (5.9) | 0.27% | — | Carlo LA Pera WP Customize Login PageAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Stored XSS.This issue affects WP Customize Login Page: from n/a through <= 1.6.5. | |
| Modificada | Alta (8.8) | 0.19% | — | Carlosminatti Delete Original Image | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This issue affects Delete Original Image: from n/a through <= 0.4. | |
| Analizada | Media (5.9) | 0.34% | — | Darkseid Beauty Parlour Management System | 14/2/2025 | 17/6/2026 | A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter. | |
| Aplazada | Alta (7.1) | 0.20% | — | Cybio GravatarlocalcacheAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request Forgery.This issue affects GravatarLocalCache: from n/a through <= 1.1.2. | |
| Analizada | Media (5.3) | 0.65% | — | 1000projects Beauty Parlour Management System | 31/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-customer-services.php of the component Customer Detail Handler. The manipulation of the argument sids[] leads to sql injection. The… | |
| Modificada | Media (6.1) | 0.50% | — | Phpgurukul Beauty Parlour Management System | 10/12/2024 | 5/7/2026 | A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters. | |
| Modificada | Crítica (9.8) | 0.62% | — | Phpgurukul Beauty Parlour Management System | 10/12/2024 | 5/7/2026 | Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter. |