Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.49% | — | Phpgurukul Hostel Management System | 28/6/2023 | 17/6/2026 | PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. | |
| Modificada | Media (4.8) | 0.44% | — | Kibokolabs Hostel | 5/6/2023 | 17/6/2026 | The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 0.59% | — | Hostel Searching Project | 17/11/2022 | 17/6/2026 | A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (8.8) | 0.53% | — | Phpgurukul Hostel Management System | 1/12/2021 | 17/6/2026 | Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover. | |
| Modificada | Media (5.4) | 3.2% | 💥 Exploit | Phpgurukul Hostel Management System | 8/10/2020 | 17/6/2026 | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. | |
| Modificada | Crítica (9.8) | 2.1% | — | Phpgurukul Hostel Management System | 8/1/2020 | 17/6/2026 | PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file. | |
| Modificada | Media (6.1) | 1.2% | — | Kibokolabs Hostel | 27/5/2019 | 17/6/2026 | XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress. |