Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.51%—Phpgurukul Vehicle Parking Management System15/5/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/add-category.php. The manipulation of the argument catename leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AplazadaAlta (8.8)0.52%—Zong YU Parking Management SystemAI12/5/202517/6/2026
The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.
AnalizadaCrítica (9.8)0.50%—Phpgurukul Vehicle Parking Management System9/5/202517/6/2026
PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.
AnalizadaMedia (4.8)0.48%—Code-projects Vehicle Parking Management System11/2/202517/6/2026
A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerability affects the function login of the component Authentication. The manipulation of the argument username leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has…
ModificadaMedia (5.4)0.34%—Phpgurukul Vehicle Parking Management System2/12/20245/7/2026
A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.
ModificadaMedia (5.4)0.37%—Phpgurukul Vehicle Parking Management System26/11/20245/7/2026
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.
ModificadaMedia (5.4)0.60%—Simple Parking Management System Project Simple Parking Management System12/7/202217/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Parking Management System 1.0. This affects an unknown part of the file /ci_spms/admin/category. The manipulation of the argument vehicle_type with the input "><script>alert("XSS")</script> leads to cross site scripting. It is…
ModificadaMedia (4.6)0.60%—Simple Parking Management System Project Simple Parking Management System12/7/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Parking Management System 1.0. Affected by this issue is some unknown functionality of the file /ci_spms/admin/search/searching/. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to…
ModificadaMedia (6.1)0.64%—Hongmen Parking Management System24/3/202217/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification code text boxes.
ModificadaMedia (5.9)1.8%—Phpgurukul Vehicle Parking Management System27/10/202117/6/2026
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3)…
ModificadaMedia (5.4)0.60%—Phpgurukul Vehicle Parking Management System27/10/202117/6/2026
A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.
ModificadaMedia (4.8)0.61%—Phpgurukul Vehicle Parking Management System19/8/202117/6/2026
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.
ModificadaCrítica (9.8)1.4%—Phpgurukul Vehicle Parking Management System20/8/202017/6/2026
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
Orbitaley — Vulnerabilidades