Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.51% | — | Fabian Hostel Management System | 20/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /allocated_rooms.php. The manipulation of the argument search_box leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Hostel Management System | 20/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostel_name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Hostel Management System | 20/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /contact_manager.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Hostel Management System | 17/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocate_room.php. The manipulation of the argument search_box leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.51% | — | Phpgurukul Hostel Management System | 17/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /includes/login-hm.inc.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Phpgurukul Hostel Management System | 17/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.51% | — | Phpgurukul Hostel Management System | 17/6/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Hostel Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/students.php. The manipulation of the argument search_box leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.1) | 0.28% | — | Goodlayers HostelAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Reflected XSS.This issue affects Goodlayers Hostel: from n/a through <= 3.1.2. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Goodlayers HostelAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Blind SQL Injection.This issue affects Goodlayers Hostel: from n/a through <= 3.1.4. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Goodlayers HostelAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This issue affects Goodlayers Hostel: from n/a through <= 3.1.2. | |
| Modificada | Crítica (9.1) | 0.44% | — | Phpgurukul Hostel Management System | 28/4/2025 | 5/7/2026 | A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely | |
| Aplazada | Alta (7.6) | 0.62% | — | Kibokolabs HostelAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel hostel allows Blind SQL Injection.This issue affects Hostel: from n/a through <= 1.1.5.6. | |
| Aplazada | Alta (7.1) | 0.31% | — | Kibokolabs HostelAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5. | |
| Aplazada | Alta (7.1) | 0.22% | — | Kibokolabs HostelAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.5. | |
| Analizada | Media (5.3) | 0.54% | — | Fabian Hostel Management System | 29/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /admin/registration.php. The manipulation of the argument fname/mname/lname leads to cross site scripting. The attack may be initiated remotely. | |
| Analizada | Media (5.3) | 0.56% | — | Fabian Hostel Management System | 19/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file room-details.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.9) | 0.80% | — | Kibokolabs Hostel | 13/7/2024 | 17/6/2026 | The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (4.3) | 0.21% | — | Kibokolabs HostelAI | 14/5/2024 | 17/6/2026 | The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can… | |
| Aplazada | Media (4.3) | 0.27% | — | Surya2developer Hostel Management ServiceAI | 15/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Surya2Developer Hostel Management Service 1.0. This issue affects some unknown processing of the file /change-password.php of the component Password Change Handler. The manipulation of the argument oldpassword leads to cross-site request forgery.… | |
| Analizada | Baja (3.7) | 0.83% | — | Surya2developer Hostel Management System | 15/3/2024 | 17/6/2026 | A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /check_availability.php of the component HTTP POST Request Handler. The manipulation of the argument oldpassword leads to observable… | |
| Analizada | Media (6.5) | 0.95% | — | Surya2developer Hostel Management System | 15/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The manipulation of the argument del leads to improper access controls. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.56% | — | Phpgurukul Hostel Management System | 10/7/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field. | |
| Modificada | Media (5.4) | 0.87% | — | Phpgurukul Hostel Management System | 10/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page. | |
| Modificada | Media (4.8) | 0.59% | — | Phpgurukul Hostel Management System | 10/7/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section. | |
| Modificada | Media (6.1) | 0.36% | — | Phpgurukul Hostel Management System | 28/6/2023 | 17/6/2026 | PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). |