Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.42%—Phpgurukul Online Course Registration5/9/202517/6/2026
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.4)0.21%💥 PoCPhpgurukul Online Shopping Portal4/9/202517/6/2026
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
AnalizadaMedia (5.5)0.44%💥 PoCPhpgurukul Beauty Parlour Management System4/9/202517/6/2026
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.5)0.44%—Phpgurukul Beauty Parlour Management System4/9/202517/6/2026
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
ModificadaAlta (7.6)0.39%💥 PoCPhpgurukul Doctor Appointment Management System3/9/202517/6/2026
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
ModificadaAlta (8.8)0.61%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.
ModificadaAlta (7.2)0.62%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter.
ModificadaMedia (6.5)0.44%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter.
ModificadaCrítica (9.1)0.47%—Phpgurukul Online Shopping Portal3/9/202517/6/2026
phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.
ModificadaAlta (7.5)0.48%—Phpgurukul Complaint Management System3/9/202517/6/2026
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.
ModificadaAlta (8.1)0.44%—Phpgurukul Complaint Management System3/9/202517/6/2026
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.
AnalizadaBaja (2)0.29%—Phpgurukul Small CRM2/9/202517/6/2026
A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public…
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of the argument sids[] results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.45%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be…
AnalizadaMedia (4.3)0.21%—Phpgurukul Employee Leave Management System2/9/202517/6/2026
PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users.
AnalizadaMedia (5.5)0.42%—Phpgurukul Beauty Parlour Management System2/9/202517/6/2026
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and…
AnalizadaBaja (2.1)0.34%—Phpgurukul User Management System1/9/202517/6/2026
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Phpgurukul Online Course Registration31/8/202517/6/2026
A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and…
AnalizadaBaja (2.1)0.35%—Phpgurukul Directory Management System29/8/202517/6/2026
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly…
ModificadaAlta (8.5)0.29%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
ModificadaMedia (6.5)0.27%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
ModificadaCrítica (9.8)0.35%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
ModificadaCrítica (9.8)0.43%—Phpgurukul Hospital Management System25/8/202517/6/2026
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
AnalizadaMedia (5.5)0.42%—Phpgurukul Online Course Registration21/8/202517/6/2026
A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Orbitaley — Vulnerabilidades