Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.67% | — | Projectworlds Railway Reservation System | 21/12/2023 | 17/6/2026 | Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Projectworlds Railway Reservation System | 21/12/2023 | 17/6/2026 | Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Projectworlds Railway Reservation System | 21/12/2023 | 17/6/2026 | Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (6.1) | 0.40% | — | Mage-people BUS Ticket Booking With Seat Reservation | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions. | |
| Modificada | Alta (8.8) | 0.74% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.63% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.63% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.74% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Alta (8.8) | 0.63% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 17/11/2023 | 17/6/2026 | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |
| Modificada | Media (5.4) | 0.61% | — | Resort Reservation System Project Resort Reservation System | 25/9/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function. | |
| Modificada | Alta (8.8) | 0.99% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with… | |
| Modificada | Crítica (9.1) | 0.56% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user. | |
| Modificada | Crítica (9.8) | 0.42% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless. | |
| Modificada | Alta (7.7) | 0.47% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services. | |
| Modificada | Alta (8.8) | 0.73% | — | Resortdata Internet Reservation Module Next Generation | 7/9/2023 | 17/6/2026 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and… | |
| Modificada | Media (4.8) | 0.44% | — | Reservation.studio | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 24/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | Resort Reservation System Project Resort Reservation System | 7/8/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Resort Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_fee.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.74% | — | Resort Reservation System Project Resort Reservation System | 7/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Resort Reservation System 1.0. This affects an unknown part of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.94% | — | Resort Reservation System Project Resort Reservation System | 6/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Phpjabbers BUS Reservation System | 3/8/2023 | 17/6/2026 | A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/pickup_id leads to cross site scripting. The attack may be launched remotely. VDB-235958 is the… | |
| Modificada | Media (6.1) | 0.43% | — | Mage-people BUS Ticket Booking With Seat Reservation | 2/8/2023 | 17/6/2026 | The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (8.8) | 0.27% | — | Pvmg Reservation.studio | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions. | |
| Modificada | Media (5.4) | 0.60% | — | Resort Reservation System Project Resort Reservation System | 18/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file ?page=rooms of the component Manage Room Page. The manipulation of the argument Cottage Number leads to cross site scripting. The attack can be… | |
| Modificada | Media (6.1) | 0.56% | — | Sscms Siteserver CMS | 24/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to… |