Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.22% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Student Record System | 14/11/2025 | 17/6/2026 | Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd,… | |
| Analizada | Media (5.4) | 0.25% | 💥 PoC | Phpgurukul Maid Hiring Management System | 3/11/2025 | 17/6/2026 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field. | |
| Modificada | Baja (2.9) | 0.59% | — | Phpgurukul News Portal | 3/11/2025 | 17/6/2026 | A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high.… | |
| Analizada | Baja (1.3) | 0.42% | — | Phpgurukul News Portal | 3/11/2025 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of… | |
| Analizada | Baja (1.9) | 0.26% | — | Phpgurukul Curfew E-pass Management System | 27/10/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (1.9) | 0.26% | — | Phpgurukul Curfew E-pass Management System | 27/10/2025 | 17/6/2026 | A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processing of the file edit-category-detail.php. The manipulation of the argument catname results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. | |
| Modificada | Baja (1.9) | 0.26% | — | Phpgurukul Curfew E-pass Management System | 27/10/2025 | 30/9/2026 | A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of the file admin-profile.php. Executing a manipulation of the argument adminname/email can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be… | |
| Analizada | Media (6.1) | 0.25% | — | Phpgurukul Bank Locker Management System | 21/10/2025 | 17/6/2026 | Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection. | |
| Modificada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 8/10/2025 | 17/6/2026 | A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The exploit has been made available to the… | |
| Modificada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 8/10/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the argument searchdata results in sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.48% | — | Phpgurukul Beauty Parlour Management System | 8/10/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/new-appointment.php. The manipulation of the argument delid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Modificada | Media (5.5) | 0.48% | — | Phpgurukul Beauty Parlour Management System | 8/10/2025 | 17/6/2026 | A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly… | |
| Modificada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 7/10/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/invoices.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 7/10/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/customer-list.php. Such manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available… | |
| Modificada | Baja (2.1) | 0.36% | — | Phpgurukul Cyber Cafe Management System | 7/10/2025 | 17/6/2026 | A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be executed… | |
| Analizada | Media (5.4) | 0.22% | — | Phpgurukul Hostel Management System | 6/10/2025 | 17/6/2026 | Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. | |
| Analizada | Baja (2.1) | 0.34% | — | Phpgurukul Beauty Parlour Management System | 6/10/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.5) | 0.26% | — | Phpgurukul Online Shopping Portal Project | 2/10/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter. | |
| Analizada | Media (4.8) | 0.26% | — | Phpgurukul User Registration & Login AND User Management System | 30/9/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters. | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Employee Record Management System | 28/9/2025 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument First name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Small CRM | 27/9/2025 | 17/6/2026 | A weakness has been identified in PHPGurukul Small CRM 4.0. This affects an unknown function of the file /forgot-password.php. Executing manipulation of the argument email can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Media (5.4) | 0.26% | — | Phpgurukul Park Ticketing Management System | 22/9/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request. |