Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul User Management System | 21/8/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Crítica (9.6) | 0.16% | — | Ads.txt Guru ConnectAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Site Request Forgery.This issue affects ads.txt Guru Connect: from n/a through <= 1.1.1. | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Beauty Parlour Management System | 15/8/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appointment.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (2.1) | 0.35% | — | Phpgurukul ZOO Management System | 15/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-foreigner-ticket.php. The manipulation of the argument visitorname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.42% | — | Phpgurukul Teachers Record Management System | 14/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.5) | 0.55% | — | Phpgurukul Boat Booking System | 1/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/add-boat.php. The manipulation of the argument boatname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Pre-school Enrollment System | 29/7/2025 | 17/6/2026 | Phpgurukul Pre-School Enrollment System 1.0 contains a SQL injection vulnerability in the /admin/password-recovery.php file. This vulnerability is attributed to the insufficient validation of user input for the username parameter. | |
| Analizada | Media (6.5) | 0.20% | — | Phpgurukul Nipah Virus Testing Management System | 29/7/2025 | 17/6/2026 | phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testing.php file, due to insufficient validation of user input for the " govtissuedid" parameter. | |
| Modificada | Alta (7.1) | 0.33% | — | Phpgurukul E-diary Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.1) | 0.33% | — | Phpgurukul Online Course Registration | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.1) | 0.26% | — | Phpgurukul Blood Bank & Donor Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.1) | 0.26% | — | Phpgurukul Small CRM | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.5) | 0.43% | — | Phpgurukul E-diary Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.1) | 0.29% | — | Phpgurukul Bank Locker Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.5) | 0.48% | — | Phpgurukul Student Result Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.1) | 0.31% | — | Phpgurukul Online Library Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.5) | 0.39% | — | Phpgurukul CAR Washing Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.5) | 0.32% | — | Phpgurukul Doctor Appointment Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack. | |
| Modificada | Alta (7.5) | 0.40% | — | Phpgurukul Student Result Management System | 28/7/2025 | 5/7/2026 | Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack. | |
| Analizada | Media (5.5) | 0.52% | — | Phpgurukul Local Services Search Engine Management System | 26/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.44% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Login and User Management System 3.3. It has been declared as critical. This vulnerability affects unknown code of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.46% | — | Phpgurukul User Registration & Login AND User Management System | 25/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3. It has been classified as critical. This affects an unknown part of the file /admin/lastthirtyays-reg-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The… |