Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie Multiplehotelreservation | 19/6/2026 | 19/8/2026 | Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT… | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie Jhotelreservation | 19/6/2026 | 19/8/2026 | Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to… | |
| Aplazada | Alta (8.1) | 0.35% | — | PreservationAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in Preservation <= 1.10 versions. | |
| Aplazada | Media (5.5) | 0.26% | — | Code-projects Hotel AND Tourism Reservation SystemAI | 5/6/2026 | 17/6/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (1.9) | 0.21% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.33% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 23/7/2026 | A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Username leads to sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 23/7/2026 | A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and… | |
| Pendiente de análisis | Alta (8.1) | 0.27% | — | HCL Hive Telco ObservabilityAIKeycloakAI | 4/6/2026 | 22/7/2026 | HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable. | |
| Aplazada | Baja (2.1) | 0.21% | — | Sourcecodester Online Boat Reservation SystemAI | 3/6/2026 | 22/7/2026 | A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Alta (7.5) | 0.43% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14. | |
| Aplazada | Media (5.5) | 0.32% | — | Code-projects Hotel AND Tourism Reservation SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.34% | — | Code-projects Hotel AND Tourism Reservation SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.50% | — | Code-projects Hotel AND Tourism Reservation SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely.… | |
| Aplazada | Alta (7.5) | 0.27% | — | Court ReservationAI | 12/5/2026 | 17/6/2026 | The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (5.3) | 0.17% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 7/5/2026 | 30/9/2026 | Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8. | |
| Aplazada | Media (5.3) | 0.24% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 30/4/2026 | 17/6/2026 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's… | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.63% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online LOT Reservation SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.3) | 0.32% | — | Webmuehle Court ReservationAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in webmuehle Court Reservation court-reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Court Reservation: from n/a through <= 1.10.11. | |
| Aplazada | Media (4.3) | 0.26% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Retrieve Embedded Sensitive Data.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through < 5.6.5. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack may be launched… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql… |