Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Phpgurukul Cyber Cafe Management System | 15/1/2026 | 17/6/2026 | A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to inject arbitrary SQL expressions. | |
| Analizada | Crítica (9.8) | 0.46% | — | Phpgurukul Cyber Cafe Management System | 15/1/2026 | 17/6/2026 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint. | |
| Analizada | Media (6.1) | 0.25% | — | Phpgurukul Cyber Cafe Management System | 15/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanitize or encode user-supplied input submitted via the uadd parameter in the add-users.php endpoint. An authenticated attacker can inject… | |
| Analizada | Media (6.1) | 0.25% | — | Phpgurukul Cyber Cafe Management System | 15/1/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affected page is… | |
| Modificada | Baja (2.1) | 0.36% | — | Phpgurukul Cyber Cafe Management System | 7/10/2025 | 17/6/2026 | A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be executed… | |
| Analizada | Media (5.5) | 0.52% | — | Phpgurukul Cyber Cafe Management System | 8/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.52% | — | Phpgurukul Cyber Cafe Management System | 8/7/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Cyber Cafe Management System | 30/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Cyber Cafe Management System | 15/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.43% | — | Phpgurukul Cyber Cafe Management System | 15/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.64% | — | Phpgurukul Cyber Cafe Management System | 6/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Media (6.9) | 0.63% | — | Phpgurukul Cyber Cafe Management System | 3/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.36% | — | Phpgurukul Cyber Cafe Management System | 13/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Phpgurukul Cyber Cafe Management System | 17/4/2024 | 17/6/2026 | SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file. | |
| Analizada | Alta (7.3) | 0.33% | — | Phpgurukul Cyber Cafe Management System | 17/4/2024 | 17/6/2026 | SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-computer-detail.php file. | |
| Analizada | Crítica (9.8) | 0.49% | — | Phpgurukul Cyber Cafe Management System | 17/4/2024 | 17/6/2026 | SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL. | |
| Analizada | Crítica (9.8) | 0.69% | — | Phpgurukul Cyber Cafe Management System | 17/4/2024 | 17/6/2026 | SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page. | |
| Analizada | Media (5.9) | 0.52% | — | Phpgurukul Cyber Cafe Management System | 17/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php. | |
| Modificada | Media (6.1) | 0.67% | — | Phpgurukul Cyber Cafe Management System | 15/6/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter. | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Phpgurukul Cyber Cafe Management System | 11/5/2022 | 17/6/2026 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication. |