Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
9817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. | |
| Analizada | Media (6.1) | 0.22% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | |
| Analizada | Alta (7.2) | 0.74% | — | Phpmyfaq | 17/11/2025 | 7/10/2026 | phpMyFAQ es una aplicación web de preguntas frecuentes (FAQ) de código abierto. Antes de la versión 4.0.14, una vulnerabilidad de inyección SQL autenticada en la funcionalidad principal de actualización de configuración de phpMyFAQ permite a un usuario privilegiado con permisos de 'Edición de Configuración' ejecutar… | |
| Aplazada | Baja (2) | 0.28% | — | Iqbolshoh Php-business-websiteAI | 17/11/2025 | 7/10/2026 | Una vulnerabilidad de seguridad ha sido detectada en el sitio web de negocios PHP de Iqbolshoh hasta 10677743a8dfc281f85291a27cf63a0bce043c24. Esto afecta una parte desconocida del archivo /admin/about.php. La manipulación conduce a una carga sin restricciones. Es posible iniciar el ataque de forma remota. El exploit… | |
| Modificada | Media (5.5) | 0.38% | — | Phpgurukul Tourism Management System | 16/11/2025 | 7/10/2026 | Se ha descubierto una falla de seguridad en PHPGurukul Tourism Management System 1.0. El elemento afectado es una función desconocida del archivo /admin/user-bookings.php. La manipulación del argumento uid resulta en inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido publicado al público y… | |
| Aplazada | Baja (2) | 0.26% | — | DouphpAI | 15/11/2025 | 17/6/2026 | A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php. | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php. | |
| Analizada | Media (6.1) | 0.22% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd,… | |
| Analizada | Media (6.9) | 0.30% | — | HP W1y47a FirmwareHP 7kw48a FirmwareHP 7kw49a FirmwareHP 7kw50a Firmware+58 | 13/11/2025 | 17/6/2026 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server. | |
| Analizada | Media (6.9) | 0.30% | — | HP W1y47a FirmwareHP 7kw48a FirmwareHP 7kw49a FirmwareHP 7kw50a Firmware+58 | 13/11/2025 | 17/6/2026 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server. | |
| Aplazada | Alta (7.5) | 0.46% | — | Processby Responsive SidebarAIPHPAI | 6/11/2025 | 7/10/2026 | Control inadecuado del nombre de fichero para la sentencia include/require en un programa PHP ('inclusión remota de ficheros PHP') vulnerabilidad en Processby Responsive Sidebar responsive-sidebar permite la inclusión local de ficheros PHP. Este problema afecta a Responsive Sidebar: desde n/a hasta menor o igual que… | |
| Analizada | Media (5.4) | 0.25% | 💥 PoC | Phpgurukul Maid Hiring Management System | 3/11/2025 | 17/6/2026 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field. | |
| Analizada | Crítica (9.8) | 0.55% | — | Car-booking-system-php Project Car-booking-system-php | 3/11/2025 | 17/6/2026 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php. | |
| Analizada | Crítica (9.4) | 0.47% | — | Car-booking-system-php Project Car-booking-system-php | 3/11/2025 | 17/6/2026 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php. | |
| Analizada | Crítica (9.8) | 0.55% | — | Car-booking-system-php Project Car-booking-system-php | 3/11/2025 | 17/6/2026 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php. | |
| Analizada | Media (5.4) | 0.29% | — | Car-booking-system-php Project Car-booking-system-php | 3/11/2025 | 17/6/2026 | Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php. | |
| Analizada | Alta (8.5) | 0.21% | — | HP Client Management Script Library | 3/11/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability. |