Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.29% | — | Thingsforrestaurants Quick Restaurant Reservations | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions. | |
| Modificada | Media (6.1) | 0.57% | — | Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System | 20/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site… | |
| Modificada | Media (5.4) | 0.78% | — | Resort Reservation System Project Resort Reservation System | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Resort Reservation System 1.0. Affected is an unknown function of the file registration.php. The manipulation of the argument fullname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.77% | — | Resort Reservation System Project Resort Reservation System | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This issue affects some unknown processing of the file view_room.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.77% | — | Fabian Simple Online Hotel Reservation System | 22/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file add_room.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-223554 is the identifier assigned to this… | |
| Modificada | Crítica (9.8) | 0.77% | — | Online Catering Reservation System Project Online Catering Reservation System | 28/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 0.92% | — | Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System | 26/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be… | |
| Modificada | Media (6.1) | 0.78% | — | Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System | 26/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /APR/signup.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The… | |
| Modificada | Media (5.1) | 0.65% | — | Online Boat Reservation System Project Online Boat Reservation System | 24/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site… | |
| Modificada | Media (4.9) | 0.83% | — | Sscms Siteserver CMS | 16/2/2023 | 17/6/2026 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. | |
| Modificada | Media (5.4) | 0.67% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 6/2/2023 | 17/6/2026 | The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 0.74% | — | Sscms Siteserver CMS | 27/1/2023 | 17/6/2026 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.97% | — | Sscms Siteserver CMS | 26/1/2023 | 17/6/2026 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | |
| Modificada | Alta (7.5) | 0.90% | — | Nodeserver Project Nodeserver | 18/1/2023 | 17/6/2026 | A vulnerability has been found in youngerheart nodeserver and classified as critical. Affected by this vulnerability is an unknown functionality of the file nodeserver.js. The manipulation leads to path traversal. The identifier of the patch is c4c0f0138ab5afbac58e03915d446680421bde28. It is recommended to apply a… | |
| Modificada | Media (6.1) | 0.60% | — | Imageserve Project Imageserve | 30/12/2022 | 17/6/2026 | A vulnerability has been found in aerouk imageserve and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument REQUEST_URI leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation… | |
| Modificada | Alta (7.5) | 0.90% | — | Imageserve Project Imageserve | 30/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in aerouk imageserve. Affected is an unknown function of the file public/viewer.php of the component File Handler. The manipulation of the argument filelocation leads to path traversal. It is possible to launch the attack remotely. The complexity of an… | |
| Modificada | Media (6.1) | 0.55% | — | Fivestarplugins Five Star Restaurant Reservations | 21/11/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could… | |
| Modificada | Crítica (9.8) | 1.3% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 8/11/2022 | 17/6/2026 | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on… | |
| Modificada | Crítica (9.8) | 1.2% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 8/11/2022 | 17/6/2026 | Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite… | |
| Modificada | Crítica (9.8) | 1.4% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 8/11/2022 | 17/6/2026 | Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the… | |
| Modificada | Crítica (9.8) | 1.5% | — | NEC Expresscluster XNEC Expresscluster X Singleserversafe | 8/11/2022 | 17/6/2026 | Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the… | |
| Modificada | Alta (8.8) | 0.53% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 3/11/2022 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options… | |
| Modificada | Media (6.5) | 0.58% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 3/11/2022 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal… | |
| Modificada | Crítica (9.8) | 39% | — | Ketchup Restaurant Reservations Project Ketchup Restaurant Reservations | 19/9/2022 | 17/6/2026 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks | |
| Modificada | Media (6.1) | 84% | — | Ketchup Restaurant Reservations Project Ketchup Restaurant Reservations | 19/9/2022 | 17/6/2026 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made |