Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—South Gate INN Online Reservation System Project South Gate INN Online Reservation System13/6/202217/6/2026
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.
ModificadaCrítica (9.8)1.6%—Food-order-and-table-reservation-system Project Food-order-and-table-reservation-system2/6/202217/6/2026
Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters.
ModificadaAlta (7.5)1.8%—Movie Seat Reservation Project Movie Seat Reservation8/4/202217/6/2026
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.
ModificadaCrítica (9.8)1.8%—Movie Seat Reservation Project Movie Seat Reservation8/4/202217/6/2026
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.
ModificadaCrítica (9.8)1.2%—South Gate INN Online Reservation System Project South Gate INN Online Reservation System24/1/202217/6/2026
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.
ModificadaMedia (5.4)0.61%—Fivestarplugins Five Star Restaurant Reservations24/1/202217/6/2026
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting…
ModificadaCrítica (9.8)1.6%—Online Railway Reservation System Project Online Railway Reservation System21/1/202217/6/2026
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
ModificadaMedia (5.4)0.62%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System20/1/202217/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.
ModificadaAlta (7.5)1.9%—Vercot Serva29/11/202117/6/2026
Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1, a related issue to CVE-2013-0145.
ModificadaCrítica (9.8)16%💥 ExploitOnline Event Booking AND Reservation System Project Online Event Booking AND Reservation System5/11/202117/6/2026
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use…
ModificadaMedia (4.3)3.9%💥 ExploitOnline Event Booking AND Reservation System Project Online Event Booking AND Reservation System5/11/202117/6/2026
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will…
ModificadaMedia (5.4)1.7%💥 PoCOnline Event Booking AND Reservation System Project Online Event Booking AND Reservation System5/11/202117/6/2026
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and…
ModificadaCrítica (9.8)3.3%💥 PoCLodging Reservation Management System Project Lodging Reservation Management System4/10/202117/6/2026
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
ModificadaAlta (7.5)2.3%—Online Catering Reservation System Project Online Catering Reservation System16/8/202117/6/2026
Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.
ModificadaMedia (5.4)0.58%—Online Catering Reservation System Project Online Catering Reservation System16/8/202117/6/2026
A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.
ModificadaMedia (6.1)5.5%💥 ExploitCatzsoft Redi Restaurant Reservation17/5/202117/6/2026
The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to…
ModificadaAlta (7.5)1.6%—Seat-reservation-system Project Seat-reservation-system17/2/202117/6/2026
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
ModificadaAlta (8.8)1.6%—Restaurant Reservation System Project Restaurant Reservation System7/1/202117/6/2026
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.
ModificadaCrítica (9.8)2.1%—Online BUS Ticket Reservation Project Online BUS Ticket Reservation14/12/202017/6/2026
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
ModificadaCrítica (9.8)6.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System2/12/202017/6/2026
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
ModificadaCrítica (9.8)5.0%—Seat Reservation System Project Seat Reservation System30/9/202017/6/2026
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
ModificadaCrítica (9.1)11%💥 ExploitSeat Reservation System Project Seat Reservation System30/9/202017/6/2026
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information…
ModificadaCrítica (9.8)3.2%—Restaurant Reservations Project Restaurant Reservations30/8/201917/6/2026
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
ModificadaAlta (7.5)4.8%💥 ExploitCP Reservation Calender Project CP Reservation Calender17/9/201517/6/2026
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data…
ModificadaBaja (3.5)0.95%—Room Reservations Project Room Reservations21/4/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remote authenticated users with the "Administer the room reservations system" permission to inject arbitrary web script or HTML via the (1) node title of a "Room Reservations Category" or (2) body of a…
Orbitaley — Vulnerabilidades