CVE & Exploit Intelligence Database

Updated 55m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
17 results Clear all
CVE-2026-1160 7.3 HIGH EPSS 0.00
Phpgurukul Directory Management System - Injection
A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
CWE-74 Jan 19, 2026
CVE-2025-9656 4.3 MEDIUM EPSS 0.00
PHPGurukul Directory Management System 2.0 - XSS
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
CWE-94 Aug 29, 2025
CVE-2025-6333 6.3 MEDIUM EPSS 0.00
PHPGurukul Directory Management System 2.0 - SQL Injection
A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Jun 20, 2025
CVE-2025-6332 6.3 MEDIUM EPSS 0.00
PHPGurukul Directory Management System 2.0 - SQL Injection
A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument del leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Jun 20, 2025
CVE-2025-6331 6.3 MEDIUM EPSS 0.00
PHPGurukul Directory Management System 1.0 - SQL Injection
A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Jun 20, 2025
CVE-2025-6330 7.3 HIGH EPSS 0.00
PHPGurukul Directory Management System 1.0 - SQL Injection
A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /searchdata.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-74 Jun 20, 2025
CVE-2025-4862 4.3 MEDIUM EPSS 0.00
Phpgurukul Directory Management System - Code Injection
A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-94 May 18, 2025
CVE-2025-4698 7.3 HIGH EPSS 0.00
PHPGurukul Directory Management System 2.0 - SQL Injection
A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/forget-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-74 May 15, 2025
CVE-2025-4697 7.3 HIGH EPSS 0.00
PHPGurukul Directory Management System 2.0 - SQL Injection
A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/edit-directory.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-74 May 15, 2025
CVE-2025-45021 5.3 MEDIUM 1 Writeup EPSS 0.00
Phpgurukul Directory Management System - SQL Injection
A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.
CWE-89 Apr 30, 2025
CVE-2024-5137 2.4 LOW 1 Writeup EPSS 0.00
PHPGurukul Directory Management System 1.0 - XSS
A vulnerability classified as problematic was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php of the component Searchbar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265213 was assigned to this vulnerability.
CWE-79 May 20, 2024
CVE-2024-5136 2.4 LOW 1 Writeup EPSS 0.00
PHPGurukul Directory Management System 1.0 - XSS
A vulnerability classified as problematic has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /admin/search-directory.php.. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265212.
CWE-79 May 20, 2024
CVE-2024-5135 7.3 HIGH 1 Writeup EPSS 0.00
PHPGurukul Directory Management System 1.0 - SQL Injection
A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265211.
CWE-89 May 20, 2024
CVE-2022-31384 9.8 CRITICAL 1 Writeup EPSS 0.01
Directory Management System v1.0 - SQL Injection
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
CWE-89 Jun 16, 2022
CVE-2022-31383 9.8 CRITICAL 1 Writeup EPSS 0.01
Directory Management System v1.0 - SQL Injection
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
CWE-89 Jun 16, 2022
CVE-2022-31382 9.8 CRITICAL 1 Writeup EPSS 0.01
Directory Management System v1.0 - SQL Injection
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
CWE-89 Jun 16, 2022
CVE-2022-29006 9.8 CRITICAL 2 PoCs Analysis NUCLEI EPSS 0.86
Directory Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CWE-89 May 11, 2022