Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2549 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.50% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit… | |
| Analizada | Baja (2) | 0.50% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Flight Ticket Booking System 1.0. This impacts an unknown function of the file /Adminadd.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp leads to sql injection. Remote exploitation of the attack is… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.59% | — | Carmelo Simple Flight Ticket Booking System | 8/3/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Alta (8.5) | 0.37% | — | Eagle-themes Eagle-bookingAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle Booking eagle-booking allows SQL Injection.This issue affects Eagle Booking: from n/a through <= 1.3.4.3. | |
| Aplazada | Alta (8.8) | 0.58% | — | Designthemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Designthemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 0.44% | — | Oplugins Booking ManagerAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Booking Manager: from n/a through <= 2.0. | |
| Aplazada | Alta (8.8) | 0.58% | — | Nextscripts Social-networks-auto-poster-facebook-twitter-gAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7. | |
| Aplazada | Alta (7.2) | 0.32% | — | Ameliabooking AmeliaAI | 5/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38. | |
| Aplazada | Alta (7.5) | 0.42% | — | Buddhathemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.8) | 0.33% | — | Rolandmurg WP Booking SystemAI | 5/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12. | |
| Aplazada | Media (5.3) | 0.83% | 💥 Exploit | Iqonic WpbookitAI | 4/3/2026 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails,… | |
| Aplazada | Alta (7.2) | 0.33% | — | Iqonic WpbookitAI | 4/3/2026 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.3) | 0.19% | — | Calibre-ebook Calibre | 27/2/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For` header is read directly… | |
| Analizada | Media (6.4) | 0.32% | — | Calibre-ebook Calibre | 27/2/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitrary HTTP headers into server responses via an unsanitized… | |
| Analizada | Media (4.8) | 0.31% | — | Audiobookshelf Mobile APP | 26/2/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges (or… | |
| Analizada | Media (4.8) | 0.32% | — | Audiobookshelf | 26/2/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can… | |
| Analizada | Media (4.8) | 0.28% | — | AudiobookshelfAudiobookshelf Mobile APP | 26/2/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges… | |
| Modificada | Alta (8.9) | 0.61% | — | Storybook | 25/2/2026 | 15/7/2026 | Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the… | |
| Analizada | Media (5.5) | 0.59% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 24/2/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Media (6.7) | 0.37% | — | Case-themes BookedAI | 20/2/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authentication Abuse.This issue affects Booked: from n/a through <= 3.0.0. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themeex Lorem Ipsum Books Media StoreAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11. | |
| Aplazada | Alta (8.8) | 0.36% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9. |