Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.15% | — | Anujk305 Medical Card Generation System | 27/6/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records via a simple GET request, without requiring a CSRF token or… | |
| Analizada | Media (6.5) | 0.15% | — | Anujk305 Medical Card Generation System | 27/6/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by sending a simple GET request without verifying the origin of the… | |
| Analizada | Media (6.1) | 0.24% | — | Anujk305 Medical Card Generation System | 27/6/2025 | 17/6/2026 | A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript. | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Medical Card Generation System | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/manage-card.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Medical Card Generation System | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/unreadenq.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Medical Card Generation System | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.1) | 0.33% | — | Phpgurukul Medical Card Generation System | 23/5/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter. | |
| Analizada | Media (6.1) | 0.27% | — | Phpgurukul Medical Card Generation System | 23/5/2025 | 17/6/2026 | Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes. | |
| Modificada | Media (5.4) | 0.25% | — | Anujk305 Medical Card Generation System | 23/5/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters. | |
| Modificada | Media (4.8) | 0.26% | — | Anujk305 Medical Card Generation System | 23/5/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters. | |
| Analizada | Media (4.6) | 0.22% | — | Anujk305 Medical Card Generation System | 19/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter. | |
| Analizada | Media (5.1) | 0.32% | — | Phpgurukul Medical Card Generation System | 23/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The… | |
| Modificada | Media (4.8) | 0.27% | — | Anujk305 Medical Card Generation System | 6/12/2024 | 17/6/2026 | PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter. | |
| Analizada | Media (5.1) | 0.44% | — | Phpgurukul Medical Card Generation System | 23/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Medical Card Generation System 1.0. Affected is an unknown function of the file /admin/search-medicalcard.php of the component Search. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (5.1) | 0.44% | — | Phpgurukul Medical Card Generation System | 23/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/view-enquiry.php of the component View Enquiry Page. The manipulation of the argument viewid leads to sql injection. The attack may be… | |
| Analizada | Media (5.1) | 0.38% | — | Phpgurukul Medical Card Generation System | 23/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/view-card-detail.php of the component Managecard View Detail Page. The manipulation of the argument viewid leads to sql injection. The attack can be initiated… | |
| Analizada | Media (5.1) | 0.41% | — | Phpgurukul Medical Card Generation System | 23/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/edit-card-detail.php of the component Managecard Edit Card Detail Page. The manipulation of the argument editid leads to sql injection. It is possible to initiate the… | |
| Analizada | Media (5.1) | 0.48% | — | Anujk305 Medical Card Generation System | 23/10/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/changeimage.php of the component Managecard Edit Image Page. The manipulation of the argument editid leads to sql injection. The attack may… | |
| Analizada | Media (5.1) | 0.43% | — | Phpgurukul Medical Card Generation System | 23/10/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/card-bwdates-reports-details.php of the component Report of Medical Card Page. The manipulation of the argument fromdate/todate… |