Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.33%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'.
AnalizadaCrítica (9.3)0.33%—Phpgurukul Online Fire Reporting System11/9/202517/6/2026
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.
AnalizadaMedia (5.1)0.21%—Phpgurukul Online Fire Reporting System11/9/202530/9/2026
XSS Almacenado en Online Fire Reporting System v1.2 de PHPGurukul, que consiste en un XSS autenticado reflejado y almacenado debido a la falta de validación adecuada de las entradas del usuario, el parámetro 'tname' vía GET y los parámetros 'teamleadname', 'teammember' y 'teamname' vía POST en el endpoint…
AnalizadaCrítica (9.3)0.33%—Phpgurukul Online Fire Reporting System11/9/202530/9/2026
Inyección SQL en el Sistema de Informes de Incendios en Línea v1.2 de PHPGurukul. Esta vulnerabilidad permite a un atacante recuperar, crear, actualizar y eliminar la base de datos a través del parámetro 'teamid' en el endpoint '/ofrs/admin/edit-team.php'.
AplazadaMedia (4.3)0.16%—Phplist SubberAI11/9/202517/6/2026
The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the bulk_action_handler function. This makes it possible for unauthenticated attackers to trigger bulk synchronization of subscription…
AplazadaBaja (2)0.25%—Lokibhardwaj Php-code-for-unlimited-file-uploadAI11/9/202517/6/2026
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made…
AnalizadaAlta (7.3)0.29%—HP Poly Lens Desktop9/9/202517/6/2026
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted.
AplazadaMedia (5.3)0.22%—Berqwp SearchproAI9/9/202517/6/2026
Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a through <= 2.2.53.
AnalizadaCrítica (9.8)2.1%—Microsoft HPC Pack9/9/202517/6/2026
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.42%—Phpgurukul Small CRM9/9/202517/6/2026
A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
ModificadaAlta (8.4)0.20%—Weiphp8/9/20255/7/2026
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
AnalizadaBaja (2.1)0.45%—Phpgurukul User Management System8/9/202517/6/2026
A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be…
AnalizadaMedia (5.5)0.41%—Phpgurukul Small CRM8/9/20251/10/2026
Se ha encontrado una falla en PHPGurukul Small CRM 4.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /get-quote.php. La ejecución de manipulación del argumento Contact puede conducir a inyección SQL. El ataque puede ejecutarse de forma remota. El exploit ha sido publicado y puede ser…
AnalizadaMedia (5.5)0.42%—Phpgurukul Online Course Registration5/9/202517/6/2026
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.4)0.21%💥 PoCPhpgurukul Online Shopping Portal4/9/202517/6/2026
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
AnalizadaAlta (7.2)0.40%—Phpversion VX Guestbook4/9/202517/6/2026
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel.
AnalizadaMedia (5.5)0.44%💥 PoCPhpgurukul Beauty Parlour Management System4/9/202517/6/2026
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.5)0.44%—Phpgurukul Beauty Parlour Management System4/9/202517/6/2026
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AnalizadaCrítica (9.4)0.53%—Ruijie Rg-es228gs-p FirmwareRuijie Rg-es209gc-p FirmwareRuijie Rg-es205gc-p FirmwareRuijie Rg-es205gc Firmware+163/9/202517/6/2026
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi.
ModificadaAlta (7.6)0.39%💥 PoCPhpgurukul Doctor Appointment Management System3/9/202517/6/2026
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
AplazadaMedia (5.3)0.22%—Peachpay FOR WoocommerceAI3/9/202517/6/2026
Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PeachPay Payments: from n/a through <= 1.117.4.
ModificadaAlta (8.8)0.61%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.
ModificadaAlta (7.2)0.62%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter.
ModificadaMedia (6.5)0.44%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter.
ModificadaCrítica (9.1)0.47%—Phpgurukul Online Shopping Portal3/9/202517/6/2026
phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.