Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.1% | — | Siteservercms Project Siteservercms | 26/8/2022 | 17/6/2026 | SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx. | |
| Modificada | Media (4.8) | 0.61% | — | Thingsforrestaurants Quick Restaurant Reservations | 20/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1. | |
| Modificada | Media (5.4) | 1.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 15/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php. | |
| Modificada | Media (5.4) | 1.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 15/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php. | |
| Modificada | Media (5.4) | 1.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 15/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php. | |
| Modificada | Media (5.4) | 1.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 15/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php. | |
| Modificada | Media (5.4) | 1.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 15/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php. | |
| Modificada | Alta (7.2) | 0.78% | — | Online Railway Reservation System Project Online Railway Reservation System | 29/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 29/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 29/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 29/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 29/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 29/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 21/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 21/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 21/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user. | |
| Modificada | Alta (7.2) | 0.96% | — | Online Railway Reservation System Project Online Railway Reservation System | 21/6/2022 | 17/6/2026 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | South Gate INN Online Reservation System Project South Gate INN Online Reservation System | 13/6/2022 | 17/6/2026 | The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution. | |
| Modificada | Crítica (9.8) | 1.6% | — | Food-order-and-table-reservation-system Project Food-order-and-table-reservation-system | 2/6/2022 | 17/6/2026 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. | |
| Modificada | Media (6.1) | 0.68% | — | Sscms Siteserver CMS | 2/6/2022 | 17/6/2026 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (5.4) | 0.70% | — | Sscms Siteserver CMS | 24/5/2022 | 17/6/2026 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 1.2% | — | Sscms Siteserver CMS | 24/5/2022 | 17/6/2026 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Sscms Siteserver CMS | 24/5/2022 | 17/6/2026 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.8% | 💥 PoC | Sscms Siteserver CMS | 3/5/2022 | 9/7/2026 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | |
| Modificada | Alta (7.5) | 1.8% | — | Movie Seat Reservation Project Movie Seat Reservation | 8/4/2022 | 17/6/2026 | Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home. |