Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
9817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.48% | — | Phpgurukul Complaint Management System | 3/9/2025 | 17/6/2026 | A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php. | |
| Modificada | Alta (8.1) | 0.44% | — | Phpgurukul Complaint Management System | 3/9/2025 | 17/6/2026 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter. | |
| Analizada | Alta (7.5) | 0.45% | — | Flightphp Flight | 3/9/2025 | 17/6/2026 | The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in the Request class constructor. The framework automatically reads the entire request body on every HTTP request, regardless of whether the application needs it. An… | |
| Analizada | Baja (2) | 0.29% | — | Phpgurukul Small CRM | 2/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of the argument sids[] results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.45% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be… | |
| Analizada | Media (4.3) | 0.21% | — | Phpgurukul Employee Leave Management System | 2/9/2025 | 17/6/2026 | PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users. | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Analizada | Baja (2.1) | 0.34% | — | Phpgurukul User Management System | 1/9/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Online Course Registration | 31/8/2025 | 17/6/2026 | A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and… | |
| Analizada | Baja (2.1) | 0.35% | — | Phpgurukul Directory Management System | 29/8/2025 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly… | |
| Aplazada | Alta (8.1) | 0.53% | — | Ovatheme IrecaAIPHPAI | 28/8/2025 | 17/6/2026 | Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP (vulnerabilidad de 'Inclusión remota de ficheros PHP') en ovatheme Ireca permite la Inclusión local de ficheros PHP. Este problema afecta a Ireca: desde n/a hasta 1.8.5. | |
| Aplazada | Alta (8.1) | 0.53% | — | Cocobas NeresaAIPHPAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Neresa neresa-wp allows PHP Local File Inclusion.This issue affects Neresa: from n/a through <= 1.3. | |
| Modificada | Alta (8.5) | 0.29% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 es vulnerable a una inyección SQL en about-us.php a través del parámetro pagetitle. | |
| Modificada | Media (6.5) | 0.27% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 es vulnerable a la inyección SQL en contact.php a través del parámetro pagetitle. | |
| Modificada | Crítica (9.8) | 0.35% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 es vulnerable a la inyección SQL en index.php a través del parámetro de username. | |
| Modificada | Crítica (9.8) | 0.43% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 es vulnerable a la inyección SQL en add-doctor.php a través del parámetro docname. | |
| Aplazada | Alta (8.7) | 0.79% | — | Phpoffice PhpspreadsheetAI | 25/8/2025 | 17/6/2026 | PhpOffice/PhpSpreadsheet es una librería PHP pura para leer y escribir archivos de hojas de cálculo. En versiones anteriores a las 1.30.0, 2.1.12, 2.4.0, 3.10.0 y 5.0.0, la SSRF podía ocurrir al leer y mostrar en el navegador un documento HTML procesado. La vulnerabilidad reside en el método setPath de la clase… | |
| Aplazada | Media (6.9) | 0.40% | — | PhprojectAI | 21/8/2025 | 17/6/2026 | Phproject es un sistema de gestión de proyectos completo y de alto rendimiento. Desde la versión 1.8.0 hasta versiones anteriores a la 1.8.3, existía una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el campo "Horas planificadas" al crear un nuevo proyecto. Al enviar una solicitud POST a /issues/new/, el… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Online Course Registration | 21/8/2025 | 17/6/2026 | Se ha encontrado una falla en PHPGurukul Online Course Registration 3.1. Esta afecta a una función desconocida del archivo /admin/session.php. Esta manipulación del argumento "sesssion" provoca una inyección SQL. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul User Management System | 21/8/2025 | 17/6/2026 | Se identificó una vulnerabilidad en PHPGurukul User Management System 1.0. Esta vulnerabilidad afecta al código desconocido del archivo /signup.php. Esta manipulación del argumento emailid provoca una inyección SQL. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. | |
| Aplazada | Alta (7.5) | 0.57% | — | Tribulant Software NewslettersAIPHPAI | 20/8/2025 | 17/6/2026 | Vulnerabilidad de control inadecuado del nombre de archivo para la declaración Include/Require en el programa PHP ('Inclusión remota de archivos PHP') en Tribulant Software Newsletters permite la inclusión local de archivos en PHP. Este problema afecta a Newsletters desde n/d hasta la versión 4.10. | |
| Aplazada | Crítica (10) | 0.39% | — | Thehp Global DNSAI | 20/8/2025 | 17/6/2026 | La vulnerabilidad de control inadecuado de la generación de código ('Inyección de código') en thehp Global DNS permite la inclusión remota de código. Este problema afecta al DNS global desde n/d hasta la versión 3.1.0. | |
| Aplazada | Alta (8.1) | 0.65% | — | Cocobsaic CalirisAIPHPAI | 20/8/2025 | 17/6/2026 | Vulnerabilidad de control incorrecto del nombre de archivo para la instrucción Include/Require en programas PHP ('Inclusión remota de archivos PHP') en CocoBasic Caliris permite la inclusión local de archivos PHP. Este problema afecta a Caliris desde n/d hasta la versión 1.5. |