Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.78%—Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System26/2/202317/6/2026
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /APR/signup.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The…
ModificadaMedia (5.1)0.65%—Online Boat Reservation System Project Online Boat Reservation System24/2/202317/6/2026
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site…
ModificadaMedia (5.4)0.67%—Oracle Restaurant Menu - Food Ordering System - Table Reservation6/2/202317/6/2026
The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.55%—Fivestarplugins Five Star Restaurant Reservations21/11/202217/6/2026
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could…
ModificadaAlta (8.8)0.53%—Oracle Restaurant Menu - Food Ordering System - Table Reservation3/11/202217/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options…
ModificadaMedia (6.5)0.58%—Oracle Restaurant Menu - Food Ordering System - Table Reservation3/11/202217/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal…
ModificadaCrítica (9.8)39%—Ketchup Restaurant Reservations Project Ketchup Restaurant Reservations19/9/202217/6/2026
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
ModificadaMedia (6.1)84%—Ketchup Restaurant Reservations Project Ketchup Restaurant Reservations19/9/202217/6/2026
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made
ModificadaMedia (4.8)0.61%—Thingsforrestaurants Quick Restaurant Reservations20/7/202217/6/2026
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
ModificadaMedia (5.4)1.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System15/7/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.
ModificadaMedia (5.4)1.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System15/7/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.
ModificadaMedia (5.4)1.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System15/7/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php.
ModificadaMedia (5.4)1.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System15/7/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.
ModificadaMedia (5.4)1.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System15/7/202217/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.
ModificadaAlta (7.2)0.78%—Online Railway Reservation System Project Online Railway Reservation System29/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System29/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System29/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System29/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System29/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System29/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System21/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System21/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System21/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.
ModificadaAlta (7.2)0.96%—Online Railway Reservation System Project Online Railway Reservation System21/6/202217/6/2026
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.
ModificadaCrítica (9.8)2.1%—South Gate INN Online Reservation System Project South Gate INN Online Reservation System13/6/202217/6/2026
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.