Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.6)0.42%—Phpgurukul User Registration & Login AND User Management System15/10/202417/6/2026
A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.
AnalizadaAlta (7.6)0.46%—Phpgurukul User Registration & Login AND User Management System15/10/202417/6/2026
A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.
AnalizadaAlta (7.6)0.58%—Phpgurukul User Registration & Login AND User Management System15/10/202417/6/2026
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.
AnalizadaMedia (5.5)0.18%—Phpgurukul User Registration & Login AND User Management System15/10/202417/6/2026
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.
AnalizadaMedia (6.5)0.41%—Phpgurukul User Registration & Login AND User Management System14/3/202417/6/2026
The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.
AnalizadaMedia (6.1)0.99%💥 PoCPhpgurukul User Registration & Login AND User Management System28/2/202417/6/2026
Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.
ModificadaCrítica (9.8)0.81%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel16/10/202317/6/2026
SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.
ModificadaMedia (5.4)0.37%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel16/10/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.
ModificadaMedia (5.4)0.51%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel6/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.
ModificadaMedia (6.1)0.41%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel29/6/202317/6/2026
A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php.
ModificadaMedia (6.1)0.36%—User Registration & Login AND User Management System Project User Registration & Login AND User Management System21/6/202317/6/2026
User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
ModificadaMedia (5.4)0.57%💥 PoCUser Registration & User Management System Project User Registration & User Management System5/12/202217/6/2026
Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages.
ModificadaMedia (6.5)0.40%—User Management System IN PHP Stored Procedure Project User Management System IN PHP Stored Procedure16/12/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.
ModificadaMedia (6.1)0.74%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel22/10/202117/6/2026
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
ModificadaAlta (8.8)0.65%—User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel26/12/202017/6/2026
A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.
ModificadaMedia (4.8)1.0%—Phpgurukul User Registration & Login AND User Management System18/11/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.
ModificadaCrítica (9.8)4.1%—Phpgurukul User Registration & Login AND User Management System16/11/202017/6/2026
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
ModificadaAlta (7.5)1.1%—Deadlock User Management System13/1/200716/6/2026
SQL injection vulnerability in Deadlock User Management System (phpdeadlock) 0.64 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Orbitaley — Vulnerabilidades