Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Projectworlds Online Movie Ticket Booking System | 3/2/2022 | 17/6/2026 | An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database. | |
| Modificada | Media (5.4) | 0.68% | — | Wpbookingsystem WP Booking System | 17/1/2022 | 17/6/2026 | The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page. | |
| Modificada | Media (6.1) | 1.2% | — | Salonbookingsystem Salon Booking System | 12/7/2021 | 17/6/2026 | The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when… | |
| Modificada | Crítica (9.8) | 2.8% | — | Online BUS Booking System Project Online BUS Booking System | 8/12/2020 | 17/6/2026 | Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege. | |
| Modificada | Crítica (9.8) | 1.3% | — | Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql | 2/12/2020 | 17/6/2026 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. | |
| Modificada | Crítica (9.8) | 1.8% | 💥 PoC | Online BUS Booking System Project Online BUS Booking System | 8/10/2020 | 17/6/2026 | In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection. | |
| Modificada | Media (6.1) | 0.87% | — | Online BUS Booking System Project Online BUS Booking System | 8/10/2020 | 17/6/2026 | In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php. | |
| Modificada | Media (5.4) | 0.60% | — | Online Hotel Booking System PRO Project Online Hotel Booking System PRO | 27/8/2020 | 17/6/2026 | Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags. | |
| Modificada | Media (6.1) | 1.2% | — | Online Hotel Booking System Project Online Hotel Booking System | 5/7/2020 | 17/6/2026 | An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields. | |
| Modificada | Alta (8.8) | 1.9% | — | Pinpoint Booking System | 10/10/2019 | 17/6/2026 | The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter. | |
| Modificada | Alta (7.2) | 0.89% | — | Wpbookingsystem WP Booking System | 20/5/2019 | 17/6/2026 | The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access. | |
| Modificada | Media (6.1) | 1.4% | — | Wpbookingsystem WP Booking System | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Dotonpaper Booking System | 22/5/2014 | 17/6/2026 | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 8/7/2011 | 16/6/2026 | SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 22/12/2009 | 16/6/2026 | SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | John Beranek Meeting Room Booking System | 2/10/2009 | 16/6/2026 | SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 18/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 18/5/2009 | 16/6/2026 | SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 20/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter. |