Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

9817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.48%—Phpgurukul Complaint Management System3/9/202517/6/2026
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.
ModificadaAlta (8.1)0.44%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.
AnalizadaAlta (7.5)0.45%—Flightphp Flight3/9/202517/6/2026
The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in the Request class constructor. The framework automatically reads the entire request body on every HTTP request, regardless of whether the application needs it. An…
AnalizadaBaja (2)0.29%—Phpgurukul Small CRM2/9/202517/6/2026
A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public…
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of the argument sids[] results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.45%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be…
AnalizadaMedia (4.3)0.21%—Phpgurukul Employee Leave Management System2/9/202517/6/2026
PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users.
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and…
AnalizadaBaja (2.1)0.34%—Phpgurukul User Management System1/9/202517/6/2026
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Phpgurukul Online Course Registration31/8/202517/6/2026
A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and…
AnalizadaBaja (2.1)0.35%—Phpgurukul Directory Management System29/8/202517/6/2026
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly…
AplazadaAlta (8.1)0.53%—Ovatheme IrecaAIPHPAI28/8/202517/6/2026
Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP (vulnerabilidad de 'Inclusión remota de ficheros PHP') en ovatheme Ireca permite la Inclusión local de ficheros PHP. Este problema afecta a Ireca: desde n/a hasta 1.8.5.
AplazadaAlta (8.1)0.53%—Cocobas NeresaAIPHPAI28/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Neresa neresa-wp allows PHP Local File Inclusion.This issue affects Neresa: from n/a through <= 1.3.
ModificadaAlta (8.5)0.29%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 es vulnerable a una inyección SQL en about-us.php a través del parámetro pagetitle.
ModificadaMedia (6.5)0.27%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 es vulnerable a la inyección SQL en contact.php a través del parámetro pagetitle.
ModificadaCrítica (9.8)0.35%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 es vulnerable a la inyección SQL en index.php a través del parámetro de username.
ModificadaCrítica (9.8)0.43%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 es vulnerable a la inyección SQL en add-doctor.php a través del parámetro docname.
AplazadaAlta (8.7)0.79%—Phpoffice PhpspreadsheetAI25/8/202517/6/2026
PhpOffice/PhpSpreadsheet es una librería PHP pura para leer y escribir archivos de hojas de cálculo. En versiones anteriores a las 1.30.0, 2.1.12, 2.4.0, 3.10.0 y 5.0.0, la SSRF podía ocurrir al leer y mostrar en el navegador un documento HTML procesado. La vulnerabilidad reside en el método setPath de la clase…
AplazadaMedia (6.9)0.40%—PhprojectAI21/8/202517/6/2026
Phproject es un sistema de gestión de proyectos completo y de alto rendimiento. Desde la versión 1.8.0 hasta versiones anteriores a la 1.8.3, existía una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el campo "Horas planificadas" al crear un nuevo proyecto. Al enviar una solicitud POST a /issues/new/, el…
AnalizadaMedia (5.5)0.42%—Phpgurukul Online Course Registration21/8/202517/6/2026
Se ha encontrado una falla en PHPGurukul Online Course Registration 3.1. Esta afecta a una función desconocida del archivo /admin/session.php. Esta manipulación del argumento "sesssion" provoca una inyección SQL. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado.
AnalizadaMedia (5.5)0.42%—Phpgurukul User Management System21/8/202517/6/2026
Se identificó una vulnerabilidad en PHPGurukul User Management System 1.0. Esta vulnerabilidad afecta al código desconocido del archivo /signup.php. Esta manipulación del argumento emailid provoca una inyección SQL. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado.
AplazadaAlta (7.5)0.57%—Tribulant Software NewslettersAIPHPAI20/8/202517/6/2026
Vulnerabilidad de control inadecuado del nombre de archivo para la declaración Include/Require en el programa PHP ('Inclusión remota de archivos PHP') en Tribulant Software Newsletters permite la inclusión local de archivos en PHP. Este problema afecta a Newsletters desde n/d hasta la versión 4.10.
AplazadaCrítica (10)0.39%—Thehp Global DNSAI20/8/202517/6/2026
La vulnerabilidad de control inadecuado de la generación de código ('Inyección de código') en thehp Global DNS permite la inclusión remota de código. Este problema afecta al DNS global desde n/d hasta la versión 3.1.0.
AplazadaAlta (8.1)0.65%—Cocobsaic CalirisAIPHPAI20/8/202517/6/2026
Vulnerabilidad de control incorrecto del nombre de archivo para la instrucción Include/Require en programas PHP ('Inclusión remota de archivos PHP') en CocoBasic Caliris permite la inclusión local de archivos PHP. Este problema afecta a Caliris desde n/d hasta la versión 1.5.