Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
2549 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.13% | — | Integrationshotelrunner Hotelrunner Booking WidgetAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en integrationshotelrunner HotelRunner Booking Widget hotelrunner permite XSS Almacenado. Este problema afecta a HotelRunner Booking Widget: desde n/a hasta menor o igual que 1.6. | |
| Aplazada | Alta (8.5) | 0.44% | — | Themefic Hydra BookingAI | 22/10/2025 | 8/10/2026 | Neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') vulnerabilidad en Themefic Hydra Booking hydra-booking permite inyección SQL. Este problema afecta a Hydra Booking: desde n/a hasta menor o igual que 1.1.10. | |
| Aplazada | Media (6.3) | 0.24% | — | Themefic Hydra BookingAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de autorización faltante en Themefic Hydra Booking hydra-booking permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Hydra Booking: desde n/a hasta menor o igual a 1.1.9. | |
| Aplazada | Media (6.4) | 0.19% | — | BG Book PublisherAI | 22/10/2025 | 8/10/2026 | El plugin Bg Book Publisher para WordPress es vulnerable a cross-site scripting almacenado a través del metadato de publicación 'book_author', renderizado mediante el shortcode '[book_author]', en todas las versiones hasta la 1.25, inclusive. Esto se debe a que el plugin no escapa correctamente el valor del metadato… | |
| Aplazada | Media (6.4) | 0.30% | — | Wpbookwidgets WP BookwidgetsAI | 15/10/2025 | 8/10/2026 | El plugin WP BookWidgets para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del shortcode 'bw_link' del plugin en todas las versiones hasta la 0.9, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en atributos proporcionados por el usuario. Esto hace posible que… | |
| Aplazada | Media (5.5) | 0.38% | — | Ywxbear Php-bookstore-website-exampleAIYwxbear PHP Basic Bookstore WebsiteAI | 11/10/2025 | 17/6/2026 | A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified… | |
| Aplazada | Media (4.5) | 0.26% | — | Oplugins Booking ManagerAI | 10/10/2025 | 8/10/2026 | El plugin de WordPress Booking Manager anterior a la versión 2.1.15 registra un shortcode que elimina reservas y hace que ese shortcode esté disponible para cualquier persona con privilegios de colaborador o superiores. Cuando se visita una página que contiene el shortcode, las reservas se eliminan. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 8/10/2026 | Una vulnerabilidad fue detectada en SourceCodester Simple E-Commerce Bookstore 1.0. El elemento afectado es una función desconocida del archivo /register.php. Realizar la manipulación del argumento register_username resulta en inyección SQL. El ataque es posible de llevar a cabo remotamente. El exploit ahora es… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en SourceCodester Simple E-Commerce Bookstore 1.0. Esto afecta una parte desconocida del archivo /index.php. La manipulación del argumento login_username conduce a inyección SQL. El ataque puede ser iniciado remotamente. El exploit está disponible públicamente y podría ser utilizado. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 8/10/2026 | Se encontró una vulnerabilidad en SourceCodester Simple E-Commerce Bookstore 1.0. El elemento afectado es una función desconocida del archivo /cart.php. La manipulación del argumento remove provoca una inyección SQL. El ataque puede ejecutarse remotamente. El exploit se ha hecho público y podría usarse. | |
| Aplazada | Alta (8.7) | 0.44% | — | Plone VoltoAIFacebook ReactAI | 2/10/2025 | 17/6/2026 | Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue… | |
| Aplazada | Media (5.3) | 0.31% | — | Themelooks FoodbookAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in themelooks FoodBook foodbook allows Retrieve Embedded Sensitive Data.This issue affects FoodBook: from n/a through <= 4.7.6. | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Bookstore Management System | 23/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument unm causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.9) | 0.22% | — | Ezee Technosys Ezee Online Hotel Booking EngineAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine online-booking-engine allows Stored XSS.This issue affects eZee Online Hotel Booking Engine: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.3) | 0.75% | 💥 Exploit | Iberezansky 3D Flipbook PDF Flipbook Viewer Flipbook Image GalleryAI | 22/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine allows Retrieve Embedded Sensitive Data.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through… | |
| Aplazada | Media (6.5) | 0.21% | — | Nextendweb Nextend Facebook ConnectAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nextendweb Nextend Facebook Connect nextend-facebook-connect allows Stored XSS.This issue affects Nextend Facebook Connect : from n/a through <= 3.1.19. | |
| Aplazada | Media (4.3) | 0.15% | — | Themespride Advanced Appointment Booking SchedulingAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themespride Advanced Appointment Booking & Scheduling advanced-appointment-booking-scheduling allows Cross Site Request Forgery.This issue affects Advanced Appointment Booking & Scheduling: from n/a through <= 2.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Themewant Easy Hotel BookingAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themewant Easy Hotel Booking easy-hotel allows DOM-Based XSS.This issue affects Easy Hotel Booking: from n/a through <= 1.9.0. | |
| Aplazada | Media (6.5) | 0.28% | — | Photonicgnostic Library-bookshelvesAI | 22/9/2025 | 30/9/2026 | Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en photonicgnostic Library Bookshelves permite XSS Almacenado. Este problema afecta a Library Bookshelves: desde n/a hasta 5.11. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Service Finder BookingsAI | 19/9/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for… | |
| Analizada | Media (5.5) | 0.42% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 18/9/2025 | 17/6/2026 | A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /check_profile.php. Executing manipulation of the argument profile_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Crítica (9.1) | 0.30% | — | Thimpress WP Hotel BookingAI | 18/9/2025 | 17/6/2026 | The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests. | |
| Analizada | Baja (2) | 0.29% | — | Facebook-riares Online Petshop Management System | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to launch the attack… | |
| Analizada | Baja (2) | 0.29% | — | Facebook-riares Online Petshop Management System | 18/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.35% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 17/9/2025 | 25/9/2026 | Se determinó una vulnerabilidad en itsourcecode E-Logbook con Health Monitoring System para COVID-19 1.0 en COVID. Esto afecta una función desconocida del archivo /print_reports_prev.PHP. La manipulación del argumento profile_id puede llevar a Cross-Site Scripting. Es posible lanzar el ataque de forma remota. El… |