Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Online Nurse Hiring System | 27/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unknown part of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Online Nurse Hiring System | 29/4/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-request.php. The manipulation of the argument viewid leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.53% | — | Phpgurukul Online Nurse Hiring System | 29/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-nurse.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (6.9) | 0.84% | — | Phpgurukul Online Nurse Hiring System | 23/2/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.57% | — | Phpgurukul Online Nurse Hiring System | 23/2/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unknown part of the file /admin/search-report-details.php. The manipulation of the argument searchinput leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Phpgurukul Online Nurse Hiring System | 23/2/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/all-request.php. The manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Online Nurse Hiring System | 23/2/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /book-nurse.php?bookid=1. The manipulation of the argument contactname leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Alta (7.2) | 0.56% | — | Phpgurukul Online Nurse Hiring System | 16/12/2024 | 17/6/2026 | Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters. | |
| Analizada | Alta (7.2) | 0.59% | — | Phpgurukul Online Nurse Hiring System | 16/12/2024 | 17/6/2026 | Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter. | |
| Analizada | Media (4.8) | 0.31% | — | Phpgurukul Online Nurse Hiring System | 16/12/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter. | |
| Analizada | Crítica (9.8) | 1.0% | 💥 PoC | Phpgurukul Online Nurse Hiring System | 12/12/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter. | |
| Analizada | Crítica (9.8) | 0.51% | — | Phpgurukul Online Nurse Hiring System | 12/12/2024 | 17/6/2026 | A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter. | |
| Modificada | Alta (7.2) | 1.0% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal. | |
| Modificada | Media (4.8) | 0.49% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal. | |
| Modificada | Media (4.8) | 0.49% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal. | |
| Modificada | Media (4.8) | 0.49% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal. | |
| Modificada | Media (4.8) | 0.48% | — | Phpgurukul Online Nurse Hiring System | 8/8/2023 | 9/7/2026 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin. |