Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Billing System | 2/12/2025 | 17/6/2026 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query. | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Billing System | 2/12/2025 | 17/6/2026 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is then concatenated directly into a backend SQL query. | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Shopping Portal | 25/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. | |
| Modificada | Baja (2) | 0.22% | — | Phpgurukul Hostel Management System | 24/11/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Analizada | Alta (7.5) | 0.23% | — | Phpgurukul Student Record System | 18/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS). | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. | |
| Analizada | Media (5.4) | 0.22% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | |
| Analizada | Media (4.6) | 0.20% | — | Phpgurukul Complaint Management System | 17/11/2025 | 17/6/2026 | PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Complaint Management System | 17/11/2025 | 17/6/2026 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. | |
| Analizada | Media (6.1) | 0.22% | — | Phpgurukul Complaint Management System | 17/11/2025 | 17/6/2026 | PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Complaint Management System | 17/11/2025 | 17/6/2026 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php. | |
| Analizada | Crítica (9.8) | 0.41% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 28/9/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Complaint Management System | 17/11/2025 | 17/6/2026 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. | |
| Analizada | Media (6.1) | 0.22% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | |
| Modificada | Media (5.5) | 0.38% | — | Phpgurukul Tourism Management System | 16/11/2025 | 30/9/2026 | A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php. | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php. |