Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

1147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.56%—Phpgurukul Hostel Management System10/7/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
ModificadaMedia (6.1)0.60%—Phpgurukul Online Security Guards Hiring System10/7/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.
ModificadaMedia (5.4)0.87%—Phpgurukul Hostel Management System10/7/202317/6/2026
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.
ModificadaMedia (4.8)0.59%—Phpgurukul Hostel Management System10/7/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
ModificadaMedia (6.1)0.36%—Phpgurukul Hostel Management System28/6/202317/6/2026
PHPgurukl Hostel Management System v1.0 es vulnerable a Cross-Site Scripting (XSS).
ModificadaMedia (6.1)0.49%—Phpgurukul Hostel Management System28/6/202317/6/2026
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
ModificadaMedia (4.8)3.7%💥 ExploitPhpgurukul Student Study Center Management System26/6/202317/6/2026
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.
ModificadaMedia (6.1)0.67%—Phpgurukul Cyber Cafe Management System15/6/202317/6/2026
Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.
ModificadaCrítica (9.8)0.55%—Phpgurukul Rail Pass Management System15/6/202317/6/2026
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be…
ModificadaCrítica (9.8)3.6%💥 ExploitPhpgurukul OLD AGE Home Management System23/5/202317/6/2026
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
ModificadaCrítica (9.8)2.1%—Phpgurukul Hospital Management System11/5/202317/6/2026
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
ModificadaCrítica (9.1)1.0%—Phpgurukul Bank Locker Management System9/4/202317/6/2026
A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.73%—Phpgurukul Bank Locker Management System9/4/202317/6/2026
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has…
ModificadaCrítica (9.8)0.74%—Phpgurukul BP Monitoring Management System8/4/202317/6/2026
A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file password-recovery.php of the component Password Recovery. The manipulation of the argument emailid/contactno leads to sql injection. The…
ModificadaCrítica (9.8)0.71%—Phpgurukul BP Monitoring Management System8/4/202317/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file change-password.php of the component Change Password Handler. The manipulation of the argument password leads to sql injection. It is possible to launch the attack…
ModificadaMedia (6.1)0.56%—Phpgurukul BP Monitoring Management System8/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file add-family-member.php of the component Add New Family Member Handler. The manipulation of the argument Member Name leads to cross site…
ModificadaMedia (6.5)0.63%—Phpgurukul BP Monitoring Management System7/4/202317/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack…
ModificadaCrítica (9.8)0.83%—Phpgurukul Park Ticketing Management System27/3/202317/6/2026
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
ModificadaMedia (4.8)0.46%—Phpgurukul Park Ticketing Management System27/3/202317/6/2026
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.
ModificadaCrítica (9.8)1.1%—Phpgurukul ART Gallery Management System15/3/202317/6/2026
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
ModificadaCrítica (9.8)0.62%—Phpgurukul BP Monitoring Management System14/3/202317/6/2026
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.
ModificadaMedia (5.4)0.56%—Phpgurukul ART Gallery Management System27/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter on the enquiry page.
ModificadaMedia (5.4)0.56%—Phpgurukul ART Gallery Management System27/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullname parameter on the enquiry page.
ModificadaCrítica (9.8)3.7%💥 ExploitPhpgurukul ART Gallery Management System27/2/202317/6/2026
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
ModificadaCrítica (9.8)1.1%—Phpgurukul ART Gallery Management System27/2/202317/6/2026
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.