Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.45% | — | Phpgurukul CAR Rental Portal | 19/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/post-avehical.php. The manipulation of the argument img1/img2/img3/img4/img5 leads to unrestricted upload. The attack may be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 1.0% | — | Projectworlds CAR Rental Project | 9/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 1.0% | — | Projectworlds CAR Rental Project | 9/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.50% | — | Codeastro CAR Rental System | 4/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of the file /returncar.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.54% | — | Fabian Simple CAR Rental System | 30/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management 1.0. Affected by this issue is some unknown functionality of the file /admin/approve.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.1) | 0.36% | — | Fabian Online CAR Rental System | 17/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cross site scripting. The attack may be initiated remotely. The… | |
| Analizada | Media (6.5) | 0.36% | — | Code-projects Online CAR Rental System | 13/1/2025 | 17/6/2026 | Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php. | |
| Analizada | Media (6.5) | 2.5% | 💥 Exploit | Code-projects Online CAR Rental System | 13/1/2025 | 17/6/2026 | In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server. | |
| Aplazada | Alta (8.8) | 1.3% | 💥 PoC | CAR Rental Management SystemAI | 7/1/2025 | 5/7/2026 | An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Media (6.9) | 0.49% | — | Fabian Online CAR Rental System | 28/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Online Car Rental System 1.0. This affects an unknown part of the file /index.php of the component GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.58% | — | Codeastro CAR Rental System | 27/12/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bookingconfirm.php. The manipulation of the argument driver_id_from_dropdown leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.68% | — | Code-projects Simple CAR Rental System | 26/12/2024 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /account.php. The manipulation of the argument email/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 0.91% | — | Fabian Simple CAR Rental System | 28/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.81% | — | Fabian Simple CAR Rental System | 23/11/2024 | 17/6/2026 | A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file /book_car.php. The manipulation of the argument fname/id_no/gender/email/phone/location leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (6.9) | 0.61% | — | Fabian Simple CAR Rental System | 2/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.3) | 0.43% | — | Phpgurukul CAR Rental Portal | 2/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.80% | — | Anisha CAR Rental | 6/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionality of the file add-vehicle.php. The manipulation of the argument Upload Image leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers CAR Rental Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Alta (8.8) | 0.96% | — | Phpjabbers CAR Rental Script | 28/8/2023 | 17/6/2026 | In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | |
| Modificada | Media (6.1) | 0.36% | — | Gzscripts CAR Rental PHP Script | 19/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in GZ Scripts Car Rental Script 1.8. Affected is an unknown function of the file /EventBookingCalendar/load.php?controller=GzFront/action=checkout/cid=1/layout=calendar/show_header=T/local=3. The manipulation of the argument… | |
| Modificada | Media (4.8) | 0.39% | — | Bestwebsoft CAR Rental | 16/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions. |