Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.26%—Phpgurukul Park Ticketing Management System22/9/202517/6/2026
A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.
AnalizadaCrítica (9.8)0.48%—Phpgurukul Park Ticketing Management System22/9/202517/6/2026
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.
AnalizadaBaja (2.1)0.45%—Phpgurukul CAR Rental Project22/9/202517/6/2026
A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. Executing manipulation of the argument autofocus can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be…
AnalizadaMedia (5.5)0.42%—Phpgurukul Small CRM18/9/202517/6/2026
A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.php. Executing manipulation of the argument subject can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.43%—Phpgurukul Online Course Registration18/9/202517/6/2026
A vulnerability was found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /my-profile.php. Performing manipulation of the argument cgpa results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.48%—Phpgurukul User Management System17/9/202525/9/2026
Se ha descubierto una falla de seguridad en PHPGurukul User Management System 1.0. Esto afecta una función desconocida del archivo /login.php. Realizar la manipulación del argumento emailid resulta en inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido liberado al público y puede ser explotado.
AplazadaMedia (6.8)0.32%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
AplazadaAlta (7.2)0.14%—HPE Aruba Networking EdgeconnectAIHPE Aruba Networking Edgeconnect Sd-wanAI16/9/202517/6/2026
A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized…
AplazadaAlta (7.2)0.64%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying…
AplazadaAlta (7.5)0.36%—HPE Aruba Networking Edgeconnect OSAI16/9/202517/6/2026
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
AplazadaAlta (8.6)0.40%—HPE Aruba Networking Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker to route potentially harmful traffic through the internal network, leading to unauthorized access or disruption of services.
AplazadaAlta (8.8)0.47%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying…
ModificadaMedia (5.4)0.18%—Phpgurukul Auto Taxi Stand Management System16/9/20255/7/2026
A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and…
ModificadaCrítica (9.8)0.56%—Phpgurukul Online Library Management System16/9/20255/7/2026
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function
AnalizadaCrítica (9.8)0.56%—Phpgurukul Online Library Management System15/9/202517/6/2026
An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System15/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/all-appointment.php. The manipulation of the argument delid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be…
AnalizadaAlta (7.3)0.20%—Phpgurukul Student Result Management System15/9/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can…
AnalizadaMedia (5.5)0.45%—Phpgurukul Beauty Parlour Management System14/9/202517/6/2026
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.5)0.41%—Phpgurukul Beauty Parlour Management System14/9/202517/6/2026
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/readenq.php. Executing manipulation of the argument delid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AnalizadaMedia (6.1)0.23%—Phpgurukul Online Shopping Portal12/9/202517/6/2026
PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.
AnalizadaMedia (5.1)0.21%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This vulnerability could allow a remote user…
AnalizadaMedia (5.1)0.21%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint '/ofrs/admin/request-details.php'. This vulnerability could allow a…
AnalizadaMedia (5.1)0.21%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'. This vulnerability could allow a remote…
AnalizadaCrítica (9.3)0.33%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'.
AnalizadaCrítica (9.3)0.33%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.