Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Projectworlds Online Movie Ticket Booking System3/2/202217/6/2026
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.
ModificadaMedia (5.4)0.68%—Wpbookingsystem WP Booking System17/1/202217/6/2026
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
ModificadaMedia (6.1)1.2%—Salonbookingsystem Salon Booking System12/7/202117/6/2026
The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when…
ModificadaCrítica (9.8)2.8%—Online BUS Booking System Project Online BUS Booking System8/12/202017/6/2026
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
ModificadaCrítica (9.8)1.3%—Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql2/12/202017/6/2026
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
ModificadaCrítica (9.8)1.8%💥 PoCOnline BUS Booking System Project Online BUS Booking System8/10/202017/6/2026
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
ModificadaMedia (6.1)0.87%—Online BUS Booking System Project Online BUS Booking System8/10/202017/6/2026
In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.
ModificadaMedia (5.4)0.60%—Online Hotel Booking System PRO Project Online Hotel Booking System PRO27/8/202017/6/2026
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
ModificadaMedia (6.1)1.2%—Online Hotel Booking System Project Online Hotel Booking System5/7/202017/6/2026
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
ModificadaAlta (8.8)1.9%—Pinpoint Booking System10/10/201917/6/2026
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
ModificadaAlta (7.2)0.89%—Wpbookingsystem WP Booking System20/5/201917/6/2026
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
ModificadaMedia (6.1)1.4%—Wpbookingsystem WP Booking System22/5/201717/6/2026
Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)3.3%💥 ExploitBestsoftinc Advance Hotel Booking System11/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
ModificadaMedia (6.5)3.6%💥 ExploitDotonpaper Booking System22/5/201417/6/2026
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.
ModificadaAlta (7.5)0.99%💥 ExploitBestsoftinc Advance Hotel Booking System8/7/201116/6/2026
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaAlta (7.5)1.0%💥 ExploitBookingcentre Booking System FOR Hotels Group22/12/200916/6/2026
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors.
ModificadaAlta (7.5)1.7%—John Beranek Meeting Room Booking System2/10/200916/6/2026
SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.00%💥 ExploitBookingcentre Booking System FOR Hotels Group18/5/200916/6/2026
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.98%💥 ExploitBookingcentre Booking System FOR Hotels Group18/5/200916/6/2026
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter.
ModificadaAlta (7.5)1.4%💥 ExploitBookingcentre Booking System FOR Hotels Group20/2/200916/6/2026
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
ModificadaMedia (4.3)1.7%💥 ExploitBookingcentre Booking System FOR Hotels Group20/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter.
Orbitaley — Vulnerabilidades