Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1065 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.32% | — | Roninwp FAT Services BookingAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through <= 5.6. | |
| Aplazada | Media (5.4) | 0.14% | — | Salonbookingsystem Salon Booking SystemAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16. | |
| Aplazada | Media (4.3) | 0.23% | — | Quanticalabs CAR Park Booking SystemAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress car-park-booking-system-for-wordpress.This issue affects Car Park Booking System for WordPress: from n/a through <= 2.6. | |
| Analizada | Media (5.4) | 0.34% | — | Wpbookingcalendar WP Booking Calendar | 17/5/2025 | 17/6/2026 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.60% | — | Roninwp FAT Services BookingAI | 16/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Services Booking fat-services-booking allows PHP Local File Inclusion.This issue affects FAT Services Booking: from n/a through <= 5.5. | |
| Aplazada | Media (4.3) | 0.34% | — | Themovation Quickcal - Appointment Booking Calendar FOR WordpressAI | 16/5/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appointment Booking Calendar for WordPress quickcal allows Retrieve Embedded Sensitive Data.This issue affects QuickCal - Appointment Booking Calendar for WordPress: from n/a through <= 1.0.15. | |
| Aplazada | Media (4.3) | 0.28% | — | Wordpresschef Salon Booking PROAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in wordpresschef Salon Booking Pro salon-booking-plugin-pro-cc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon Booking Pro: from n/a through <= 10.10.2. | |
| Analizada | Media (4.8) | 0.26% | — | Salonbookingsystem Salon Booking System | 15/5/2025 | 17/6/2026 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is… | |
| Analizada | Media (6.5) | 0.51% | — | Wpbookingcalendar Secure Downloads | 15/5/2025 | 17/6/2026 | The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php. | |
| Analizada | Media (4.8) | 0.31% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 15/5/2025 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.5) | 0.39% | — | Phpjabbers Event Booking Calendar | 8/5/2025 | 17/6/2026 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Aplazada | Alta (7.5) | 0.77% | — | Nicdark Hotel BookingAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Inclusion.This issue affects Hotel Booking: from n/a through <= 3.6. | |
| Aplazada | Media (6.5) | 0.26% | — | Markkinchin Beds24 Online BookingAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markkinchin Beds24 Online Booking beds24-online-booking allows Stored XSS.This issue affects Beds24 Online Booking: from n/a through <= 2.0.29. | |
| Aplazada | Media (4.3) | 0.17% | — | Thimpress WP Hotel BookingAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9. | |
| Analizada | Media (6.9) | 0.52% | — | Phpgurukul Online DJ Booking Management System | 5/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.52% | — | Phpgurukul Online DJ Booking Management System | 5/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/user-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul Online DJ Booking Management System | 2/5/2025 | 17/6/2026 | A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Boat Booking System | 1/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The manipulation of the argument Status leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Boat Booking System | 1/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Boat Booking System | 1/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The manipulation of the argument bid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (4.8) | 0.37% | — | Fabian Simple Movie Ticket Booking System | 29/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation of the argument prize leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to… | |
| Analizada | Media (4.8) | 0.35% | — | Fabian Theater Seat Booking System | 29/4/2025 | 17/6/2026 | A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The manipulation of the argument cancelcustomername leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit… | |
| Modificada | Crítica (9.8) | 0.78% | — | Phpgurukul Online Banquet Booking System | 28/4/2025 | 5/7/2026 | An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component | |
| Analizada | Media (5) | 0.26% | — | Codeastro BUS Ticket Booking System | 28/4/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing. | |
| Analizada | Crítica (9.8) | 0.54% | — | Codeastro BUS Ticket Booking System | 25/4/2025 | 17/6/2026 | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder. |