Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)0.44%—Phpgurukul Hostel Management System28/4/20255/7/2026
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely
AnalizadaMedia (5.3)0.54%—Fabian Hostel Management System29/12/202417/6/2026
A vulnerability, which was classified as problematic, has been found in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /admin/registration.php. The manipulation of the argument fname/mname/lname leads to cross site scripting. The attack may be initiated remotely.
AnalizadaMedia (5.3)0.56%—Fabian Hostel Management System19/12/202417/6/2026
A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file room-details.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaBaja (3.7)0.83%—Surya2developer Hostel Management System15/3/202417/6/2026
A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /check_availability.php of the component HTTP POST Request Handler. The manipulation of the argument oldpassword leads to observable…
AnalizadaMedia (6.5)0.95%—Surya2developer Hostel Management System15/3/202417/6/2026
A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The manipulation of the argument del leads to improper access controls. It is possible to launch the attack remotely. The exploit has…
ModificadaMedia (6.1)0.56%—Phpgurukul Hostel Management System10/7/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
ModificadaMedia (5.4)0.87%—Phpgurukul Hostel Management System10/7/202317/6/2026
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.
ModificadaMedia (4.8)0.59%—Phpgurukul Hostel Management System10/7/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
ModificadaMedia (6.1)0.36%—Phpgurukul Hostel Management System28/6/202317/6/2026
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (6.1)0.49%—Phpgurukul Hostel Management System28/6/202317/6/2026
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
ModificadaAlta (8.8)0.53%—Phpgurukul Hostel Management System1/12/202117/6/2026
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
ModificadaMedia (5.4)3.2%💥 ExploitPhpgurukul Hostel Management System8/10/202017/6/2026
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
ModificadaCrítica (9.8)2.1%—Phpgurukul Hostel Management System8/1/202017/6/2026
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
Orbitaley — Vulnerabilidades