Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · phpgurukul

phpgurukul

· 107 Critical

Total CVEs

1,062

Critical

107

Products

87

Search All CVEs →

1,062

Products (87)

hospital management system62 CVEszoo management system37 CVEsart gallery management system36 CVEsonline shopping portal33 CVEsonline fire reporting system32 CVEscomplaint management system31 CVEsstudent record system29 CVEsbeauty parlour management system28 CVEsland record system25 CVEspre-school enrollment system25 CVEsvehicle parking management system24 CVEsuser registration \& login and user management system24 CVEsdairy farm shop management system24 CVEsapartment visitors management system21 CVEsnipah virus testing management system21 CVEsold age home management system21 CVEscyber cafe management system20 CVEspark ticketing management system20 CVEsemployee record management system19 CVEssmall crm19 CVEscovid19 testing management system19 CVEsboat booking system18 CVEsbank locker management system17 CVEsmen salon management system17 CVEsdirectory management system17 CVEsonline nurse hiring system17 CVEsrestaurant table booking system17 CVEsemergency ambulance hiring portal17 CVEshostel management system15 CVEsrail pass management system15 CVEsmaid hiring management system15 CVEse-diary management system15 CVEsonline course registration14 CVEsnews portal13 CVEsjob portal12 CVEsonline birth certificate system12 CVEsdaily expense tracker system12 CVEsdoctor appointment management system12 CVEsauto\/taxi stand management system11 CVEsmedical card generation system11 CVEscurfew e-pass management system10 CVEsteacher subject allocation management system10 CVEsonline banquet booking system9 CVEscompany visitor management system9 CVEsteachers record management system9 CVEsonline dj booking management system9 CVEsbp monitoring management system8 CVEshuman metapneumovirus testing management system8 CVEsstudent result management system8 CVEsclient management system8 CVEsnews portal project7 CVEsonline marriage registration system7 CVEsonline security guards hiring system7 CVEsblood bank \& donor management system7 CVEsonline notes sharing system7 CVEstourism management system7 CVEsbus pass management system7 CVEsonline course registration system6 CVEsonline library management system6 CVEsvehicle record management system5 CVEsonline shopping portal project5 CVEsuser management system5 CVEscar rental portal5 CVEslocal services search engine management system4 CVEsnotice board system4 CVEsifsc code finder4 CVEsvehicle record system3 CVEsstudent management system3 CVEstime table generator system3 CVEsstudent study center management system3 CVEscredit card application management system2 CVEsonline notes sharing management system2 CVEshuman metapneumovirus2 CVEsbilling system2 CVEscar washing management system2 CVEsemployee leave management system1 CVEsgym management system1 CVEscovid 19 testing management system1 CVEsonline railway catering management system1 CVEsonline book store1 CVEscar rental project1 CVEsblood donor management system1 CVEsstaff leave management system1 CVEsmedical card system1 CVEselearning system1 CVEsteacher subject allocation system1 CVEsauto taxi stand management system1 CVEs

Recent Vulnerabilities

View all 1,062
CVE-2024-51226MEDIUM 6.1

A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Search parameter.

CVE-2024-51225MEDIUM 4.8

A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the brandname parameter.

CVE-2024-51224MEDIUM 4.8

Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum and enginenumber parameters.

CVE-2024-51223MEDIUM 4.8

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Mobile Number parameter.

CVE-2024-51222MEDIUM 4.8

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

CVE-2026-3403LOW 2.4

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVE-2026-3402LOW 2.4

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-70064HIGH 8.8

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data.

CVE-2025-70063MEDIUM 6.5

The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iterating the 'viewid' integer.

CVE-2025-70062MEDIUM 6.5

PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.

CVE-2024-55270HIGH 8.8

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

CVE-2024-55271LOW 3.5

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint.

CVE-2026-2179MEDIUM 4.7

A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-2134MEDIUM 4.7

A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

CVE-2026-2088HIGH 7.3

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-1550MEDIUM 6.3

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVE-2026-1424MEDIUM 4.7

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVE-2025-70899MEDIUM 6.5

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.

CVE-2026-1160HIGH 7.3

A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-1142MEDIUM 4.3

A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-1141MEDIUM 6.3

A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used.

CVE-2025-70893HIGH 8.8

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to inject arbitrary SQL expressions.

CVE-2025-70892CRITICAL 9.8

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

CVE-2025-70891MEDIUM 6.1

A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanitize or encode user-supplied input submitted via the uadd parameter in the add-users.php endpoint. An authenticated attacker can inject arbitrary JavaScript code that is persistently stored in the database. The malicious payload is triggered when a privileged user clicks the View button on the view-allusers.php page.

CVE-2025-70890MEDIUM 6.1

A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affected page is accessed.