Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | South Gate INN Online Reservation System Project South Gate INN Online Reservation System | 13/6/2022 | 17/6/2026 | The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution. | |
| Modificada | Crítica (9.8) | 1.6% | — | Food-order-and-table-reservation-system Project Food-order-and-table-reservation-system | 2/6/2022 | 17/6/2026 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. | |
| Modificada | Alta (7.5) | 1.8% | — | Movie Seat Reservation Project Movie Seat Reservation | 8/4/2022 | 17/6/2026 | Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home. | |
| Modificada | Crítica (9.8) | 1.8% | — | Movie Seat Reservation Project Movie Seat Reservation | 8/4/2022 | 17/6/2026 | Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | South Gate INN Online Reservation System Project South Gate INN Online Reservation System | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters. | |
| Modificada | Media (5.4) | 0.61% | — | Fivestarplugins Five Star Restaurant Reservations | 24/1/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting… | |
| Modificada | Crítica (9.8) | 1.6% | — | Online Railway Reservation System Project Online Railway Reservation System | 21/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. | |
| Modificada | Media (5.4) | 0.62% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 20/1/2022 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters. | |
| Modificada | Alta (7.5) | 1.9% | — | Vercot Serva | 29/11/2021 | 17/6/2026 | Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1, a related issue to CVE-2013-0145. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Online Event Booking AND Reservation System Project Online Event Booking AND Reservation System | 5/11/2021 | 17/6/2026 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use… | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Online Event Booking AND Reservation System Project Online Event Booking AND Reservation System | 5/11/2021 | 17/6/2026 | An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will… | |
| Modificada | Media (5.4) | 1.7% | 💥 PoC | Online Event Booking AND Reservation System Project Online Event Booking AND Reservation System | 5/11/2021 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 PoC | Lodging Reservation Management System Project Lodging Reservation Management System | 4/10/2021 | 17/6/2026 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication. | |
| Modificada | Alta (7.5) | 2.3% | — | Online Catering Reservation System Project Online Catering Reservation System | 16/8/2021 | 17/6/2026 | Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php. | |
| Modificada | Media (5.4) | 0.58% | — | Online Catering Reservation System Project Online Catering Reservation System | 16/8/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar. | |
| Modificada | Media (6.1) | 5.5% | 💥 Exploit | Catzsoft Redi Restaurant Reservation | 17/5/2021 | 17/6/2026 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to… | |
| Modificada | Alta (7.5) | 1.6% | — | Seat-reservation-system Project Seat-reservation-system | 17/2/2021 | 17/6/2026 | Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information. | |
| Modificada | Alta (8.8) | 1.6% | — | Restaurant Reservation System Project Restaurant Reservation System | 7/1/2021 | 17/6/2026 | Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Online BUS Ticket Reservation Project Online BUS Ticket Reservation | 14/12/2020 | 17/6/2026 | SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields. | |
| Modificada | Crítica (9.8) | 6.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 2/12/2020 | 17/6/2026 | The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability. | |
| Modificada | Crítica (9.8) | 5.0% | — | Seat Reservation System Project Seat Reservation System | 30/9/2020 | 17/6/2026 | Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files. | |
| Modificada | Crítica (9.1) | 11% | 💥 Exploit | Seat Reservation System Project Seat Reservation System | 30/9/2020 | 17/6/2026 | An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information… | |
| Modificada | Crítica (9.8) | 3.2% | — | Restaurant Reservations Project Restaurant Reservations | 30/8/2019 | 17/6/2026 | The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | CP Reservation Calender Project CP Reservation Calender | 17/9/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data… | |
| Modificada | Baja (3.5) | 0.95% | — | Room Reservations Project Room Reservations | 21/4/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remote authenticated users with the "Administer the room reservations system" permission to inject arbitrary web script or HTML via the (1) node title of a "Room Reservations Category" or (2) body of a… |