Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Seat-reservation-system Project Seat-reservation-system17/2/202117/6/2026
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
ModificadaAlta (8.8)1.6%—Restaurant Reservation System Project Restaurant Reservation System7/1/202117/6/2026
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.
ModificadaCrítica (9.8)2.1%—Online BUS Ticket Reservation Project Online BUS Ticket Reservation14/12/202017/6/2026
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
ModificadaCrítica (9.8)6.1%—Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System2/12/202017/6/2026
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
ModificadaCrítica (9.8)2.2%—HP Storeserv Management Console26/10/202017/6/2026
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR…
ModificadaCrítica (9.8)5.0%—Seat Reservation System Project Seat Reservation System30/9/202017/6/2026
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
ModificadaCrítica (9.1)11%💥 ExploitSeat Reservation System Project Seat Reservation System30/9/202017/6/2026
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information…
ModificadaMedia (6.1)12%💥 ExploitTileservergl1/7/202017/6/2026
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaCrítica (9.8)1.6%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, which is for executing programs when certain events are triggered.
ModificadaAlta (8.8)1.0%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.
ModificadaAlta (8.8)0.50%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and password, admin ones included; Create/Delete users; Enable/Disable Services; Set a rogue update proxy; and Shutdown the server.
ModificadaCrítica (9.8)0.91%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbitrary files via the fileName parameter.
ModificadaMedia (6.1)0.68%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter.
ModificadaAlta (7.5)0.93%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.
ModificadaMedia (6.1)0.68%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Reflected via the filename parameter. Collaborate is Stored via the displayname parameter. Deletemultiple is Reflected via the files parameter. Share is Reflected…
ModificadaAlta (8.8)0.50%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to the public for uploading and deleting files and directories.
ModificadaMedia (6.1)0.86%—Genesys Eservices Chat11/10/201917/6/2026
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).
ModificadaCrítica (9.8)3.2%—Restaurant Reservations Project Restaurant Reservations30/8/201917/6/2026
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
ModificadaMedia (6.1)1.0%—Django JS Reverse Project Django JS Reserve23/8/201917/6/2026
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
ModificadaMedia (6.3)0.97%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.2)1.4%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.3)1.6%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (8.8)1.6%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaMedia (4.8)0.55%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.