Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.24% | — | Favethemes Homey | 2/5/2025 | 17/6/2026 | The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the homey_reservation_del() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul OLD AGE Home Management System | 28/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.59% | — | Phpgurukul OLD AGE Home Management System | 28/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.5) | 0.27% | — | Alleythemes Home ServicesAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Home Services home-services allows DOM-Based XSS.This issue affects Home Services: from n/a through <= 1.2.6. | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul OLD AGE Home Management System | 7/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-scdetails.php. The manipulation of the argument contnum leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul OLD AGE Home Management System | 7/4/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul OLD AGE Home Management System | 7/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Qcn9070 FirmwareQualcomm Qcn9072 FirmwareQualcomm Qcn9074 FirmwareQualcomm Qcn9100 Firmware+265 | 7/4/2025 | 17/6/2026 | Transient DOS may occur while parsing SSID in action frames. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+145 | 7/4/2025 | 17/6/2026 | Transient DOS may occur while parsing extended IE in beacon. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform Firmware+56 | 7/4/2025 | 17/6/2026 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | |
| Analizada | Media (5.5) | 0.11% | — | Qualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+306 | 7/4/2025 | 17/6/2026 | There may be information disclosure during memory re-allocation in TZ Secure OS. | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul OLD AGE Home Management System | 4/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Favethemes HomeyAI | 4/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1. | |
| Analizada | Media (5.3) | 0.50% | — | Phpgurukul OLD AGE Home Management System | 4/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/profile.php. The manipulation of the argument adminname/contactnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.28% | — | Itning Student-homework-management-system | 3/4/2025 | 17/6/2026 | A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (4.8) | 0.33% | — | Itning Student-homework-management-system | 3/4/2025 | 17/6/2026 | A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been classified as problematic. Affected is an unknown function of the file /shw_war/fileupload of the component Edit Job Page. The manipulation of the argument Course leads to cross site scripting. It is possible to launch the… | |
| Aplazada | Alta (8.8) | 0.29% | 💥 PoC | Xiaomi SmarthomeAI | 27/3/2025 | 17/6/2026 | An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code. | |
| Aplazada | Alta (7.1) | 0.31% | — | Homejunction Spatialmatch IDXAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in homejunction SpatialMatch IDX spatialmatch-free-lifestyle-search allows Reflected XSS.This issue affects SpatialMatch IDX: from n/a through <= 3.0.9. | |
| Analizada | Media (6.9) | 0.43% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/eligibility.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-services.php. The manipulation of the argument sertitle leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.47% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/manage-scdetails.php. The manipulation of the argument namesc leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.47% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-services.php. The manipulation of the argument sertitle leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul OLD AGE Home Management System | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… |