Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.83%—IBM Observability With Instana4/10/202317/6/2026
IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.
ModificadaMedia (5.4)0.61%—Resort Reservation System Project Resort Reservation System25/9/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function.
ModificadaAlta (7.5)0.85%—Redhat Network Observability15/9/202317/6/2026
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
ModificadaAlta (8.8)0.99%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with…
ModificadaCrítica (9.1)0.56%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
ModificadaCrítica (9.8)0.42%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
ModificadaAlta (7.7)0.47%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
ModificadaAlta (8.8)0.73%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and…
ModificadaMedia (4.8)0.44%—Reservation.studio30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions.
ModificadaMedia (6.1)0.39%—Oracle Restaurant Menu - Food Ordering System - Table Reservation24/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 versions.
ModificadaCrítica (9.8)0.74%—Resort Reservation System Project Resort Reservation System7/8/202317/6/2026
A vulnerability has been found in SourceCodester Resort Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_fee.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.74%—Resort Reservation System Project Resort Reservation System7/8/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Resort Reservation System 1.0. This affects an unknown part of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.94%—Resort Reservation System Project Resort Reservation System6/8/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been…
ModificadaMedia (6.1)2.5%💥 ExploitPhpjabbers BUS Reservation System3/8/202317/6/2026
A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/pickup_id leads to cross site scripting. The attack may be launched remotely. VDB-235958 is the…
ModificadaMedia (6.1)0.43%—Mage-people BUS Ticket Booking With Seat Reservation2/8/202317/6/2026
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
ModificadaAlta (8.8)0.27%—Pvmg Reservation.studio11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions.
ModificadaMedia (5.4)0.60%—Resort Reservation System Project Resort Reservation System18/6/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file ?page=rooms of the component Manage Room Page. The manipulation of the argument Cottage Number leads to cross site scripting. The attack can be…
ModificadaCrítica (9.8)0.29%—Thingsforrestaurants Quick Restaurant Reservations22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions.
ModificadaMedia (6.1)0.57%—Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System20/5/202317/6/2026
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site…
ModificadaMedia (5.4)0.78%—Resort Reservation System Project Resort Reservation System28/4/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Resort Reservation System 1.0. Affected is an unknown function of the file registration.php. The manipulation of the argument fullname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.77%—Resort Reservation System Project Resort Reservation System28/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This issue affects some unknown processing of the file view_room.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.77%—Fabian Simple Online Hotel Reservation System22/3/202317/6/2026
A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file add_room.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-223554 is the identifier assigned to this…
ModificadaCrítica (9.1)8.6%💥 ExploitIBM Observability With Instana3/3/202317/6/2026
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
ModificadaCrítica (9.8)0.77%—Online Catering Reservation System Project Online Catering Reservation System28/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the…
ModificadaCrítica (9.8)0.92%—Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System26/2/202317/6/2026
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be…
Orbitaley — Vulnerabilidades