Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

2549 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.34%—Facebook-julykringcadayona Student Information System17/9/202525/9/2026
Se ha encontrado una vulnerabilidad en itsourcecode Student Information System 1.0. El elemento afectado es una función desconocida del archivo /leveledit1.php. Dicha manipulación del argumento level_id conduce a inyección SQL. El ataque puede realizarse de forma remota. El exploit se ha divulgado al público y puede…
AnalizadaBaja (2.1)0.36%—Emiloi E-logbook With Health Monitoring System FOR Covid-1914/9/202517/6/2026
A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /stc-log-keeper/check_profile.php of the component POST Request Handler. The manipulation of the argument profile_id results in cross site scripting. The attack…
AplazadaMedia (5.3)0.29%—Salonbookingsystem Salon Booking SystemAI11/9/202517/6/2026
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.1)0.11%—Cristiano Zanca Woocommerce Booking Bundle HoursAI9/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce Booking Bundle Hours: from n/a through 0.7.4.
AplazadaMedia (6.5)0.32%—Wpsimplebookingcalendar WP Simple Booking CalendarAI9/9/202517/6/2026
Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calendar: from n/a through <= 2.0.13.
AnalizadaMedia (5.5)0.53%—Emiloi E-logbook With Health Monitoring System FOR Covid-199/9/202517/6/2026
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202517/6/2026
A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dymanic_table.php. Such manipulation of the argument scripts leads to cross site scripting. The attack may be…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202517/6/2026
A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_th.php. This manipulation of the argument scripts causes cross site scripting. The attack is possible to be carried out remotely.…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202517/6/2026
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts results in cross site scripting. The attack can be…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202530/9/2026
Una vulnerabilidad fue detectada en itsourcecode POS Point of Sale System 1.0. El elemento afectado es una función desconocida del archivo /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. La manipulación del argumento scripts resulta en cross-site scripting. Es posible iniciar el ataque…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System6/9/202530/9/2026
Se identificó una vulnerabilidad en itsourcecode POS Point of Sale System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.PHP. La manipulación del argumento scripts conduce a cross-site scripting. La explotación remota del ataque…
AnalizadaBaja (2)0.29%—Facebook-kimmymatillano Point OF Sale System6/9/202517/6/2026
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation of the argument scripts results in cross site scripting. The attack may be…
AnalizadaBaja (2)0.29%—Facebook-kimmymatillano Point OF Sale System6/9/202517/6/2026
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit is publicly…
AnalizadaBaja (2)0.30%—Facebook-kimmymatillano Point OF Sale System5/9/202517/6/2026
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts causes cross site scripting. The attack can be initiated remotely.…
AnalizadaBaja (2)0.29%—Facebook-kimmymatillano Point OF Sale System5/9/202517/6/2026
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument scripts results in cross site scripting. It is possible to…
AplazadaMedia (6.5)0.17%—Course Finder Course Booking PlatformAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0.
AnalizadaAlta (7.2)0.40%—Phpversion VX Guestbook4/9/202517/6/2026
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel.
AplazadaMedia (6.5)0.17%—Deetronix Booking Ultra PROAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.21.
AnalizadaMedia (5.5)0.41%—Janobe Online Book Store30/8/202517/6/2026
A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
AnalizadaMedia (5.5)0.41%—Facebook-julykringcadayona Student Information System30/8/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
AplazadaMedia (6.4)0.20%—Booking CalendarAI28/8/202517/6/2026
El complemento Booking Calendar para WordPress es vulnerable a cross-site scripting (XSS) almacenado a través de la configuración en todas las versiones hasta la 10.14.1 incluida, debido a una depuración de entrada y un escape de salida insuficientes. Esto permite a atacantes autenticados, con acceso de administrador…
AplazadaMedia (6.5)0.17%—Ameliabooking Booking System TrafftAI27/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') en ameliabooking Booking System Trafft que permite XSS almacenado. Este problema afecta a Booking System Trafft desde n/d hasta la versión 1.0.14.
AnalizadaAlta (8.8)0.46%—Audiobookshelf22/8/202517/6/2026
Audiobookshelf es un servidor de audiolibros autoalojado de código abierto. En las versiones 2.6.0 a 2.26.3, la aplicación no restringe correctamente las URL de redireccionamiento de devolución de llamada durante la autenticación OIDC. Un atacante puede manipular un enlace de inicio de sesión que haga que…
AplazadaCrítica (9.8)0.56%—Magepeopleteam Taxi Booking Manager FOR WoocommerceAI20/8/202517/6/2026
La vulnerabilidad de omisión de autenticación mediante una ruta o canal alternativo en magepeopleteam Taxi Booking Manager for WooCommerce permite el abuso de autenticación. Este problema afecta a Taxi Booking Manager para WooCommerce desde n/d hasta la versión 1.3.0.
ModificadaAlta (7.2)0.44%💥 PoCVcita Online Booking & Scheduling Calendar20/8/202517/6/2026
La vulnerabilidad de subida sin restricciones de archivos con tipo peligroso en vcita Online Booking &amp; Scheduling Calendar for WordPress by vcita permite el uso de archivos maliciosos. Este problema afecta a Online Booking &amp; Scheduling Calendar for WordPress by vcita desde la versión n/d hasta la 4.5.3.