Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.8%—Movie Seat Reservation Project Movie Seat Reservation8/4/202217/6/2026
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.
ModificadaCrítica (9.8)1.2%—South Gate INN Online Reservation System Project South Gate INN Online Reservation System24/1/202217/6/2026
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.
ModificadaMedia (5.4)0.61%—Fivestarplugins Five Star Restaurant Reservations24/1/202217/6/2026
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting…
ModificadaCrítica (9.8)1.6%—Online Railway Reservation System Project Online Railway Reservation System21/1/202217/6/2026
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
ModificadaMedia (5.4)0.62%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System20/1/202217/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.
ModificadaAlta (7.5)0.53%—Emuse - Eservices / Envoice Project Emuse - Eservices / Envoice29/12/202117/6/2026
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
ModificadaCrítica (9.8)1.3%—Emuse - Eservices / Envoice Project Emuse - Eservices / Envoice29/12/202117/6/2026
Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot…
ModificadaAlta (7.2)1.1%—HP Storeserv Management Console10/12/202117/6/2026
A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays being managed are not impacted by this…
ModificadaCrítica (9.8)16%💥 ExploitOnline Event Booking AND Reservation System Project Online Event Booking AND Reservation System5/11/202117/6/2026
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use…
ModificadaMedia (4.3)3.9%💥 ExploitOnline Event Booking AND Reservation System Project Online Event Booking AND Reservation System5/11/202117/6/2026
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will…
ModificadaMedia (5.4)1.7%💥 PoCOnline Event Booking AND Reservation System Project Online Event Booking AND Reservation System5/11/202117/6/2026
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and…
ModificadaAlta (7.5)0.99%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via…
ModificadaAlta (7.5)1.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.
ModificadaAlta (7.5)1.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code…
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)2.2%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)3.3%💥 PoCLodging Reservation Management System Project Lodging Reservation Management System4/10/202117/6/2026
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
ModificadaAlta (7.5)2.3%—Online Catering Reservation System Project Online Catering Reservation System16/8/202117/6/2026
Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.
ModificadaMedia (5.4)0.58%—Online Catering Reservation System Project Online Catering Reservation System16/8/202117/6/2026
A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.
ModificadaMedia (6.1)5.5%💥 ExploitCatzsoft Redi Restaurant Reservation17/5/202117/6/2026
The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to…
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
Orbitaley — Vulnerabilidades