Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.49%—Phpgurukul Hostel Management System28/6/202317/6/2026
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
ModificadaMedia (4.8)0.44%—Kibokolabs Hostel5/6/202317/6/2026
The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaCrítica (9.8)0.59%—Hostel Searching Project17/11/202217/6/2026
A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaAlta (8.8)0.53%—Phpgurukul Hostel Management System1/12/202117/6/2026
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
ModificadaMedia (5.4)3.2%💥 ExploitPhpgurukul Hostel Management System8/10/202017/6/2026
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
ModificadaCrítica (9.8)2.1%—Phpgurukul Hostel Management System8/1/202017/6/2026
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
ModificadaMedia (6.1)1.2%—Kibokolabs Hostel27/5/201917/6/2026
XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress.
Orbitaley — Vulnerabilidades