Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Codepeople WP Time Slots Booking FormAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.42. | |
| Aplazada | Alta (7.5) | 0.51% | — | Magepeopleteam WpbookinglyAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly service-booking-manager allows PHP Local File Inclusion.This issue affects WpBookingly: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.6) | 0.38% | — | Wpdevelop Booking CalendarAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar: from n/a through <= 10.14.15. | |
| Aplazada | Alta (8.8) | 0.34% | — | Uhotelbooking SystemAI | 12/3/2026 | 17/6/2026 | uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection… | |
| Aplazada | Alta (7.5) | 0.46% | — | JetbookingAI | 11/3/2026 | 17/6/2026 | The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.5) | 0.41% | — | Timely DEV Appointment Booking CalendarAI | 11/3/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent the `append_where_sql` parameter from… | |
| Analizada | Baja (2.1) | 0.49% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql injection. The attack may be initiated remotely. The exploit has been made public… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may… | |
| Analizada | Baja (2) | 0.50% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit… | |
| Analizada | Baja (2) | 0.50% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Flight Ticket Booking System 1.0. This impacts an unknown function of the file /Adminadd.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp leads to sql injection. Remote exploitation of the attack is… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Alta (8.5) | 0.37% | — | Eagle-themes Eagle-bookingAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle Booking eagle-booking allows SQL Injection.This issue affects Eagle Booking: from n/a through <= 1.3.4.3. | |
| Aplazada | Alta (8.8) | 0.58% | — | Designthemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Designthemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 0.44% | — | Oplugins Booking ManagerAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Booking Manager: from n/a through <= 2.0. | |
| Aplazada | Alta (7.2) | 0.32% | — | Ameliabooking AmeliaAI | 5/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38. | |
| Aplazada | Alta (7.5) | 0.42% | — | Buddhathemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.8) | 0.33% | — | Rolandmurg WP Booking SystemAI | 5/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12. | |
| Aplazada | Alta (8.8) | 0.36% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9. | |
| Aplazada | Media (6.5) | 0.33% | — | Themewant Easy Hotel BookingAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in themewant Easy Hotel Booking easy-hotel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Hotel Booking: from n/a through <= 1.9.2. | |
| Aplazada | Media (4.4) | 0.26% | — | Tennis Court BookingsAI | 19/2/2026 | 17/6/2026 | The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… |