Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.48% | — | Phpgurukul Park Ticketing Management System | 22/9/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request. | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul CAR Rental Project | 22/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. Executing manipulation of the argument autofocus can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Small CRM | 18/9/2025 | 17/6/2026 | A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.php. Executing manipulation of the argument subject can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.43% | — | Phpgurukul Online Course Registration | 18/9/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /my-profile.php. Performing manipulation of the argument cgpa results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.48% | — | Phpgurukul User Management System | 17/9/2025 | 25/9/2026 | A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument emailid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. | |
| Modificada | Media (5.4) | 0.18% | — | Phpgurukul Auto Taxi Stand Management System | 16/9/2025 | 5/7/2026 | A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and… | |
| Modificada | Crítica (9.8) | 0.56% | — | Phpgurukul Online Library Management System | 16/9/2025 | 5/7/2026 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function | |
| Analizada | Crítica (9.8) | 0.56% | — | Phpgurukul Online Library Management System | 15/9/2025 | 17/6/2026 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Beauty Parlour Management System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/all-appointment.php. The manipulation of the argument delid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be… | |
| Analizada | Alta (7.3) | 0.20% | — | Phpgurukul Student Result Management System | 15/9/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can… | |
| Analizada | Media (5.5) | 0.45% | — | Phpgurukul Beauty Parlour Management System | 14/9/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Beauty Parlour Management System | 14/9/2025 | 17/6/2026 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/readenq.php. Executing manipulation of the argument delid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Analizada | Media (6.1) | 0.23% | — | Phpgurukul Online Shopping Portal | 12/9/2025 | 17/6/2026 | PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart. | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This vulnerability could allow a remote user… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint '/ofrs/admin/request-details.php'. This vulnerability could allow a… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'. This vulnerability could allow a remote… | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint… | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'. | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Small CRM | 9/9/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul User Management System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be… | |
| Analizada | Media (5.5) | 0.41% | — | Phpgurukul Small CRM | 8/9/2025 | 1/10/2026 | A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argument Contact can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. |