Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.42% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request. | |
| Analizada | Alta (7.6) | 0.58% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request. | |
| Analizada | Media (5.5) | 0.18% | — | Phpgurukul User Registration & Login AND User Management System | 15/10/2024 | 17/6/2026 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. | |
| Analizada | Media (6.5) | 0.41% | — | Phpgurukul User Registration & Login AND User Management System | 14/3/2024 | 17/6/2026 | The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks. | |
| Analizada | Media (6.1) | 0.99% | 💥 PoC | Phpgurukul User Registration & Login AND User Management System | 28/2/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar. | |
| Modificada | Crítica (9.8) | 0.81% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 16/10/2023 | 17/6/2026 | SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. | |
| Modificada | Media (5.4) | 0.37% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 16/10/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page. | |
| Modificada | Media (5.4) | 0.51% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 6/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field. | |
| Modificada | Media (6.1) | 0.41% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 29/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | |
| Modificada | Media (6.1) | 0.36% | — | User Registration & Login AND User Management System Project User Registration & Login AND User Management System | 21/6/2023 | 17/6/2026 | User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php. | |
| Modificada | Media (5.4) | 0.57% | 💥 PoC | User Registration & User Management System Project User Registration & User Management System | 5/12/2022 | 17/6/2026 | Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages. | |
| Modificada | Media (6.5) | 0.40% | — | User Management System IN PHP Stored Procedure Project User Management System IN PHP Stored Procedure | 16/12/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account. | |
| Modificada | Media (6.1) | 0.74% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 22/10/2021 | 17/6/2026 | Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields. | |
| Modificada | Alta (8.8) | 0.65% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 26/12/2020 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1. | |
| Modificada | Media (4.8) | 1.0% | — | Phpgurukul User Registration & Login AND User Management System | 18/11/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1. | |
| Modificada | Crítica (9.8) | 4.1% | — | Phpgurukul User Registration & Login AND User Management System | 16/11/2020 | 17/6/2026 | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | |
| Modificada | Alta (7.5) | 1.1% | — | Deadlock User Management System | 13/1/2007 | 16/6/2026 | SQL injection vulnerability in Deadlock User Management System (phpdeadlock) 0.64 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |