Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Movie Seat Reservation Project Movie Seat Reservation | 8/4/2022 | 17/6/2026 | Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | South Gate INN Online Reservation System Project South Gate INN Online Reservation System | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters. | |
| Modificada | Media (5.4) | 0.61% | — | Fivestarplugins Five Star Restaurant Reservations | 24/1/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting… | |
| Modificada | Crítica (9.8) | 1.6% | — | Online Railway Reservation System Project Online Railway Reservation System | 21/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. | |
| Modificada | Media (5.4) | 0.62% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 20/1/2022 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters. | |
| Modificada | Alta (7.5) | 0.53% | — | Emuse - Eservices / Envoice Project Emuse - Eservices / Envoice | 29/12/2021 | 17/6/2026 | Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Emuse - Eservices / Envoice Project Emuse - Eservices / Envoice | 29/12/2021 | 17/6/2026 | Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot… | |
| Modificada | Alta (7.2) | 1.1% | — | HP Storeserv Management Console | 10/12/2021 | 17/6/2026 | A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays being managed are not impacted by this… | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Online Event Booking AND Reservation System Project Online Event Booking AND Reservation System | 5/11/2021 | 17/6/2026 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use… | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Online Event Booking AND Reservation System Project Online Event Booking AND Reservation System | 5/11/2021 | 17/6/2026 | An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will… | |
| Modificada | Media (5.4) | 1.7% | 💥 PoC | Online Event Booking AND Reservation System Project Online Event Booking AND Reservation System | 5/11/2021 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and… | |
| Modificada | Alta (7.5) | 0.99% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via… | |
| Modificada | Alta (7.5) | 1.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network. | |
| Modificada | Alta (7.5) | 1.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network. | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code… | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 2.2% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 PoC | Lodging Reservation Management System Project Lodging Reservation Management System | 4/10/2021 | 17/6/2026 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication. | |
| Modificada | Alta (7.5) | 2.3% | — | Online Catering Reservation System Project Online Catering Reservation System | 16/8/2021 | 17/6/2026 | Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php. | |
| Modificada | Media (5.4) | 0.58% | — | Online Catering Reservation System Project Online Catering Reservation System | 16/8/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar. | |
| Modificada | Media (6.1) | 5.5% | 💥 Exploit | Catzsoft Redi Restaurant Reservation | 17/5/2021 | 17/6/2026 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to… | |
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… |