Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.61% | — | Fabian Simple CAR Rental System | 2/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (8.8) | 1.5% | — | CAR Rental System Project CAR Rental System | 8/4/2022 | 17/6/2026 | Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter. | |
| Modificada | Alta (8.8) | 1.8% | — | Online CAR Rental System Project Online CAR Rental System | 4/4/2022 | 17/6/2026 | Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code. | |
| Modificada | Media (6.1) | 1.2% | — | Bestsoftinc CAR Rental System | 5/7/2020 | 17/6/2026 | An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields. | |
| Modificada | Crítica (9.8) | 1.6% | — | Projectworlds Official CAR Rental System | 6/4/2020 | 17/6/2026 | Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt. | |
| Modificada | Alta (7.2) | 1.1% | — | Projectworlds Official CAR Rental System | 6/4/2020 | 17/6/2026 | An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files. |