Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.39% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 26/9/2026 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 25/9/2026 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Lemonldap NG PortalAI | 16/8/2026 | 26/8/2026 | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state… | |
| Aplazada | Media (5.4) | 0.23% | — | Logo Software Industry AND Trade E-logo Purchasing PortalAI | 6/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue affects e-Logo Purchasing Portal: before 1.52. | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The manipulation of the argument filename results in sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. The attack may be initiated remotely. The exploit has been made available to the… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-details.php of the component Parameter Handler. The manipulation of the argument orderid results in sql injection. It is possible to launch the attack remotely. | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /payment-method.php of the component Parameter Handler. Performing a manipulation of the argument paymethod results in sql injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Shopping Portal | 25/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. | |
| Analizada | Media (5.4) | 0.22% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. | |
| Analizada | Crítica (9.8) | 0.41% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 28/9/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. | |
| Analizada | Media (6.5) | 0.26% | — | Phpgurukul Online Shopping Portal Project | 2/10/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter. | |
| Analizada | Media (6.1) | 0.23% | — | Phpgurukul Online Shopping Portal | 12/9/2025 | 17/6/2026 | PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart. | |
| Analizada | Media (5.4) | 0.21% | 💥 PoC | Phpgurukul Online Shopping Portal | 4/9/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php. | |
| Modificada | Crítica (9.1) | 0.47% | — | Phpgurukul Online Shopping Portal | 3/9/2025 | 17/6/2026 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. |