Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.39% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters. | |
| Modificada | Media (6.1) | 0.39% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Analizada | Media (4.7) | 0.41% | — | Phpjabbers Event Booking Calendar | 19/2/2025 | 17/6/2026 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Analizada | Media (6.5) | 0.55% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Media (6.1) | 0.46% | — | Phpjabbers Event Booking Calendar | 19/2/2025 | 17/6/2026 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers Event Booking Calendar | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Aplazada | Alta (7) | 0.14% | — | ABB System 800xaAIVideonetAI | 10/2/2025 | 17/6/2026 | A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used. An attacker who successfully exploited the vulnerability could, in the worst case scenario, stop or manipulate the video feed. This issue affects System 800xA: 5.1.X; System 800xA: 6.0.3.X; System… | |
| Analizada | Crítica (9.8) | 0.88% | 💥 PoC | Phpjabbers Cinema Booking System | 6/2/2025 | 17/6/2026 | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation. | |
| Analizada | Media (5.4) | 0.28% | 💥 PoC | Phpjabbers Cinema Booking System | 6/2/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request. | |
| Analizada | Crítica (9.3) | 0.76% | 💥 PoC | Phpjabbers Cinema Booking System | 6/2/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection,… | |
| Analizada | Media (6.1) | 0.45% | 💥 PoC | Phpjabbers Cinema Booking System | 6/2/2025 | 17/6/2026 | PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks. | |
| Modificada | Crítica (9.3) | 0.62% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+15 | 6/2/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm5430 Firmware+20 | 3/2/2025 | 17/6/2026 | Memory corruption may occour while generating test pattern due to negative indexing of display ID. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+28 | 3/2/2025 | 17/6/2026 | Memory corruption while handling IOCTL call from user-space to set latency level. | |
| Analizada | Alta (7) | 0.07% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+33 | 3/2/2025 | 17/6/2026 | Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+156 | 3/2/2025 | 17/6/2026 | Memory corruption while configuring a Hypervisor based input virtual device. | |
| Aplazada | Media (4.3) | 0.36% | — | TabbyAI | 16/1/2025 | 17/6/2026 | An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails. | |
| Aplazada | Alta (7.1) | 0.17% | — | Shabboscommerce Shabbos AND YOM TOVAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in shabboscommerce Shabbos and Yom Tov shabbos-and-yom-tov allows Stored XSS.This issue affects Shabbos and Yom Tov: from n/a through <= 1.9. | |
| Analizada | Media (6.1) | 0.38% | — | Syedfakharabbas Backlink Monitoring Manager | 9/1/2025 | 17/6/2026 | The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (8.6) | 0.36% | — | TabbyAI | 8/1/2025 | 17/6/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is… | |
| Aplazada | Media (5.1) | 0.35% | — | ABB Ac500 V3AI | 7/1/2025 | 17/6/2026 | An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 version mentioned. A successfully authenticated attacker can use this vulnerability to read system wide files and configuration All AC500 V3 products (PM5xxx) with firmware version… | |
| Aplazada | Alta (8.6) | 0.51% | — | Mediawiki TabbernewAI | 6/1/2025 | 17/6/2026 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+47 | 6/1/2025 | 17/6/2026 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+47 | 6/1/2025 | 17/6/2026 | Memory corruption when IOCTL call is invoked from user-space to read board data. | |
| Aplazada | Alta (8.6) | 0.31% | — | TabbyAI | 26/12/2024 | 17/6/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential security vulnerabilities. The application currently holds powerful permissions… |