Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1065 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.45% | — | Anisha Online Appointment Booking System | 13/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. This vulnerability affects unknown code of the file /cancelbookingpatient.php. The manipulation of the argument appointment leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.45% | — | Anisha Online Appointment Booking System | 13/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affects an unknown part of the file /ulocateus.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.5) | 0.27% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 9/7/2025 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcfm_redirect_to_setup function in all versions up to, and including, 6.7.16. This makes it possible for… | |
| Analizada | Baja (2.1) | 0.25% | — | Codeastro Online Movie Ticket Booking System | 7/7/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (6.5) | 0.23% | — | Codepeople Booking Calendar Contact FormAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.58. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Aonetheme Service Finder BookingAI | 4/7/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.This issue affects Service Finder Booking: from n/a through <= 6.1. | |
| Aplazada | Alta (7.5) | 0.46% | — | Booking XAI | 4/7/2025 | 17/6/2026 | The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in versions 1.0 to 1.1.2. This makes it possible for unauthenticated attackers to download all plugin data, including user accounts, user meta, and PayPal credentials, by… | |
| Analizada | Media (5.5) | 0.49% | — | Anisha Online Hotel Booking | 30/6/2025 | 17/6/2026 | A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The manipulation of the argument uname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.5) | 0.72% | — | Nicdark Hotel BookingAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Inclusion.This issue affects Hotel Booking: from n/a through <= 3.7. | |
| Analizada | Media (6.1) | 0.26% | — | Phpgurukul Online DJ Booking Management System | 24/6/2025 | 17/6/2026 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-queries.php. | |
| Analizada | Media (6.1) | 0.26% | — | Phpgurukul Online DJ Booking Management System | 24/6/2025 | 17/6/2026 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-detail.php and /admin/invoice-generating.php. | |
| Analizada | Media (6.5) | 0.33% | — | Phpgurukul Online DJ Booking Management System | 24/6/2025 | 17/6/2026 | PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/request-details.php. | |
| Aplazada | Media (4.3) | 0.15% | — | Oganro Pixelbeds Channel Manager AND Hotel Booking EngineAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-channel-manager-booking-engine allows Cross Site Request Forgery.This issue affects PixelBeds Channel Manager and Hotel Booking Engine: from n/a through <= 1.0. | |
| Aplazada | Media (6.4) | 0.29% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 14/6/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to… | |
| Analizada | Baja (2) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this issue is some unknown functionality of the file /check-status.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The… | |
| Analizada | Baja (1.9) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-table.php. The manipulation of the argument tableno leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Analizada | Baja (1.9) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/manage-subadmins.php. The manipulation of the argument fullname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Baja (1.9) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit… | |
| Aplazada | Media (4.3) | 0.14% | — | Codepeople WP Time Slots Booking FormAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Cross Site Request Forgery.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.30. | |
| Aplazada | Alta (8.5) | 0.32% | — | Themefic Hydra BookingAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.10. | |
| Aplazada | Media (5.9) | 0.26% | — | Deetronix Booking Ultra PROAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.20. | |
| Aplazada | Media (4.3) | 0.18% | — | Fasterthemes Fastbook Responsive Appointment Booking AND Scheduling SystemAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FasterThemes FastBook fastbook-responsive-appointment-booking-and-scheduling-system allows Cross Site Request Forgery.This issue affects FastBook: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 2/6/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.8. | |
| Modificada | Crítica (9.8) | 0.48% | — | Phpgurukul Restaurant Table Booking System | 23/5/2025 | 17/6/2026 | PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Smartcms BUS Ticket Booking With Seat ReservationAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticket Booking with Seat Reservation for WooCommerce scw-bus-seat-reservation allows SQL Injection.This issue affects Bus Ticket Booking with Seat Reservation for WooCommerce: from n/a through <= 1.7. |