Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
9817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | XSS Almacenado en Online Fire Reporting System v1.2 de PHPGurukul, que consiste en un XSS autenticado reflejado y almacenado debido a la falta de validación adecuada de las entradas del usuario, el parámetro 'tname' vía GET y los parámetros 'teamleadname', 'teammember' y 'teamname' vía POST en el endpoint… | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | Inyección SQL en el Sistema de Informes de Incendios en Línea v1.2 de PHPGurukul. Esta vulnerabilidad permite a un atacante recuperar, crear, actualizar y eliminar la base de datos a través del parámetro 'teamid' en el endpoint '/ofrs/admin/edit-team.php'. | |
| Aplazada | Media (4.3) | 0.16% | — | Phplist SubberAI | 11/9/2025 | 17/6/2026 | The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the bulk_action_handler function. This makes it possible for unauthenticated attackers to trigger bulk synchronization of subscription… | |
| Aplazada | Baja (2) | 0.25% | — | Lokibhardwaj Php-code-for-unlimited-file-uploadAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Alta (7.3) | 0.29% | — | HP Poly Lens Desktop | 9/9/2025 | 17/6/2026 | A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted. | |
| Aplazada | Media (5.3) | 0.22% | — | Berqwp SearchproAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a through <= 2.2.53. | |
| Analizada | Crítica (9.8) | 2.1% | — | Microsoft HPC Pack | 9/9/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Small CRM | 9/9/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Modificada | Alta (8.4) | 0.20% | — | Weiphp | 8/9/2025 | 5/7/2026 | WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul User Management System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be… | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Small CRM | 8/9/2025 | 1/10/2026 | Se ha encontrado una falla en PHPGurukul Small CRM 4.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /get-quote.php. La ejecución de manipulación del argumento Contact puede conducir a inyección SQL. El ataque puede ejecutarse de forma remota. El exploit ha sido publicado y puede ser… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Online Course Registration | 5/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.4) | 0.21% | 💥 PoC | Phpgurukul Online Shopping Portal | 4/9/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php. | |
| Analizada | Alta (7.2) | 0.40% | — | Phpversion VX Guestbook | 4/9/2025 | 17/6/2026 | An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel. | |
| Analizada | Media (5.5) | 0.44% | 💥 PoC | Phpgurukul Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.44% | — | Phpgurukul Beauty Parlour Management System | 4/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Crítica (9.4) | 0.53% | — | Ruijie Rg-es228gs-p FirmwareRuijie Rg-es209gc-p FirmwareRuijie Rg-es205gc-p FirmwareRuijie Rg-es205gc Firmware+16 | 3/9/2025 | 17/6/2026 | A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi. | |
| Modificada | Alta (7.6) | 0.39% | 💥 PoC | Phpgurukul Doctor Appointment Management System | 3/9/2025 | 17/6/2026 | In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment. | |
| Aplazada | Media (5.3) | 0.22% | — | Peachpay FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PeachPay Payments: from n/a through <= 1.117.4. | |
| Modificada | Alta (8.8) | 0.61% | — | Phpgurukul Complaint Management System | 3/9/2025 | 17/6/2026 | phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter. | |
| Modificada | Alta (7.2) | 0.62% | — | Phpgurukul Complaint Management System | 3/9/2025 | 17/6/2026 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter. | |
| Modificada | Media (6.5) | 0.44% | — | Phpgurukul Complaint Management System | 3/9/2025 | 17/6/2026 | phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter. | |
| Modificada | Crítica (9.1) | 0.47% | — | Phpgurukul Online Shopping Portal | 3/9/2025 | 17/6/2026 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. |