Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.76%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This affects an unknown part of the file /admin/forgot-password.php of the component Forgot Password Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the…
AnalizadaCrítica (9.8)0.77%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The manipulation of the argument searchdata leads to sql injection.…
AnalizadaMedia (6.1)0.67%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability classified as problematic was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The manipulation of the argument searchdata leads to cross site scripting. The…
AnalizadaCrítica (9.8)0.80%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaMedia (6.1)0.67%—Phpgurukul Emergency Ambulance Hiring Portal30/3/202417/6/2026
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Hire an Ambulance Page. The manipulation of the argument Patient Name/Relative Name/Relative Phone Number/City/State/Message leads to cross site…
ModificadaAlta (8.8)1.4%💥 PoCPhpgurukul Online Shopping Portal18/8/202317/6/2026
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.
ModificadaAlta (8.8)1.1%💥 PoCPhpgurukul Online Shopping Portal1/8/202317/6/2026
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
ModificadaCrítica (9.1)0.68%—Phpgurukul Online Shopping Portal10/7/202317/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely.…
ModificadaCrítica (9.8)1.1%—Phpgurukul Online Shopping Portal18/2/202217/6/2026
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
ModificadaMedia (6.1)0.58%—Shopping Portal Project Shopping Portal5/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in examples_support/editable_ajax.php, and the (3) PHP_SELF…
ModificadaAlta (7.5)1.5%—Phpgurukul Online Shopping Portal27/10/202117/6/2026
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
ModificadaAlta (7.5)2.2%💥 ExploitUseasdf 4444 Hotel Booking Portal11/4/201216/6/2026
SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.
ModificadaAlta (7.5)1.0%💥 ExploitScriptsfeed Recipes Listing Portal2/11/201116/6/2026
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.3%—Preprojects PRE E-learning Portal10/3/201016/6/2026
SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.
ModificadaAlta (7.5)1.00%💥 ExploitTourismscripts Tourism Script Accomodation Hotel Booking Portal Script18/1/201016/6/2026
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php.
ModificadaMedia (6.5)3.9%💥 ExploitScriptsfeed Recipes Listing Portal12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
ModificadaMedia (5)1.3%—Preprojects PRE E-learning Portal4/2/200916/6/2026
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
ModificadaMedia (6.8)0.94%💥 ExploitCustomcms Gaming Portal19/9/200816/6/2026
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.5%💥 ExploitDrunken Golem Gaming Portal30/1/200716/6/2026
PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Orbitaley — Vulnerabilidades