Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.34%—Wpbookingsystem WP Booking SystemAI23/7/202623/7/2026
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
AplazadaAlta (8.8)0.40%—Salonbookingsystem Salon Booking SystemAI10/7/202610/7/2026
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code…
AplazadaMedia (4.3)0.28%—Salonbookingsystem Salon Booking SystemAI1/7/20261/7/2026
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
AplazadaAlta (7.3)0.30%—Salonbookingsystem Salon Booking SystemAI17/6/202617/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
AplazadaAlta (7.5)0.39%—Salonbookingsystem Salon Booking SystemAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
AplazadaMedia (5.5)0.27%—Code-projects Simple Flight Ticket Booking SystemAI8/6/202623/7/2026
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaAlta (7.5)0.55%—Salonbookingsystem Salon Booking SystemAI2/5/202617/6/2026
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it…
AplazadaMedia (5.3)0.26%—Dotonpaper Pinpoint Booking SystemAI8/4/202624/7/2026
Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5.
AplazadaAlta (8.1)0.26%—Wordpresschef Salon Booking System PROAI25/3/202617/6/2026
Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.
AplazadaAlta (8.8)0.34%—Uhotelbooking SystemAI12/3/202617/6/2026
uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection…
AnalizadaBaja (2.1)0.49%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.59%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql injection. The attack may be initiated remotely. The exploit has been made public…
AnalizadaMedia (5.5)0.59%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
AnalizadaMedia (5.5)0.59%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may…
AnalizadaBaja (2)0.50%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit…
AnalizadaBaja (2)0.50%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A security vulnerability has been detected in code-projects Simple Flight Ticket Booking System 1.0. This impacts an unknown function of the file /Adminadd.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp leads to sql injection. Remote exploitation of the attack is…
AnalizadaMedia (5.5)0.59%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and…
AnalizadaMedia (5.5)0.59%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit has been released to the…
AnalizadaMedia (5.5)0.59%—Carmelo Simple Flight Ticket Booking System8/3/202617/6/2026
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be…
AplazadaMedia (5.8)0.33%—Rolandmurg WP Booking SystemAI5/3/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.
AplazadaMedia (6.5)0.41%—Salonbookingsystem Salon Booking SystemAI22/1/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.
AnalizadaBaja (2)0.32%—Anisha Online Appointment Booking System19/12/202517/6/2026
A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the file /admin/deletemanager.php. The manipulation of the argument managername results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.36%—Anisha Online Appointment Booking System17/12/202517/6/2026
A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /admin/deletemanagerclinic.php. Performing manipulation of the argument clinic results in sql injection. The attack can be initiated remotely. The exploit has been…
AplazadaMedia (4.3)0.16%—Salonbookingsystem Salon Booking SystemAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3.
AplazadaMedia (5.3)0.24%—Course Booking SystemAI8/11/202517/6/2026
The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php file in all versions up to, and including, 6.1.5. This makes it possible for unauthenticated attackers to directly access the file and obtain an export of all booking data.