Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.9)0.48%—Phpgurukul Small CRMAI13/9/202616/9/2026
A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is…
ModificadaBaja (2.1)0.38%—Phpgurukul Small CRM31/12/202517/6/2026
A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
AnalizadaMedia (6.5)0.24%—Phpgurukul Small CRM17/11/202517/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
AnalizadaMedia (6.1)0.22%—Phpgurukul Small CRM17/11/202517/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Small CRM17/11/202517/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Small CRM17/11/202517/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
AnalizadaMedia (5.5)0.42%—Phpgurukul Small CRM27/9/202517/6/2026
A weakness has been identified in PHPGurukul Small CRM 4.0. This affects an unknown function of the file /forgot-password.php. Executing manipulation of the argument email can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.
AnalizadaMedia (5.5)0.42%—Phpgurukul Small CRM18/9/202517/6/2026
A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.php. Executing manipulation of the argument subject can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.42%—Phpgurukul Small CRM9/9/202517/6/2026
A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Phpgurukul Small CRM8/9/20251/10/2026
A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argument Contact can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AnalizadaBaja (2)0.29%—Phpgurukul Small CRM2/9/202517/6/2026
A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
ModificadaAlta (7.1)0.26%—Phpgurukul Small CRM28/7/20255/7/2026
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
AnalizadaMedia (6.9)0.45%—Phpgurukul Small CRM27/5/202517/6/2026
A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown processing of the file /admin/manage-tickets.php. The manipulation of the argument aremark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (6.9)0.45%—Phpgurukul Small CRM27/5/202517/6/2026
A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-password.php. The manipulation of the argument oldpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…
ModificadaMedia (5.4)0.23%—Phpgurukul Small CRM10/2/202517/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.
AnalizadaMedia (5.3)0.44%—Phpgurukul Small CRM29/12/202417/6/2026
A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (5.3)0.51%—Phpgurukul Small CRM29/12/202417/6/2026
A vulnerability was found in PHPGurukul Small CRM 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/quote-details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (5.3)0.51%—Phpgurukul Small CRM29/12/202417/6/2026
A vulnerability has been found in PHPGurukul Small CRM 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaCrítica (9.8)0.92%—Phpgurukul Small CRM12/4/202417/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the component Registration Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (8.8)1.3%—Phpgurukul Small CRM12/4/202417/6/2026
A vulnerability classified as critical was found in PHPGurukul Small CRM 3.0. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.63%—Small CRM Project Small CRM29/12/202317/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
ModificadaMedia (5.4)0.36%—Small CRM Project Small CRM20/10/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
ModificadaMedia (5.4)0.57%—Small CRM Project Small CRM4/10/202317/6/2026
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
ModificadaMedia (5.4)0.55%—Small CRM Project Small CRM27/9/202317/6/2026
A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
ModificadaMedia (6.1)0.49%—Small CRM Project Small CRM28/6/202317/6/2026
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).