Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
1066 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.39% | — | Anujk305 Online Banquet Booking System | 30/9/2023 | 17/6/2026 | Una vulnerabilidad ha sido encontrada en Online Banquet Booking System 1.0 y clasificada como problemática. Una función desconocida del archivo /book-services.php del componente Service Booking es afectada por esta vulnerabilidad. La manipulación del argumento "message" conduce a Cross-Site Scripting (XSS). El ataque… | |
| Modificada | Media (6.1) | 0.39% | — | Phpgurukul Online Banquet Booking System | 30/9/2023 | 17/6/2026 | Una vulnerabilidad fue encontrada en Online Banquet Booking System 1.0 y clasificada como problemática. Una función desconocida del archivo /view-booking-detail.php del componente Account Detail Handler. La manipulación del argumento nombre de usuario conduce a Cross-Site Scripting (XSS). Es posible lanzar el ataque… | |
| Modificada | Media (5.4) | 0.41% | — | Projectworlds Online Movie Ticket Booking System | 28/9/2023 | 17/6/2026 | Online Movie Ticket Booking System v1.0 es vulnerable a una vulnerabilidad de Cross-Site Scripting almacenado autenticado. | |
| Modificada | Crítica (9.8) | 0.98% | — | Projectworlds Online Movie Ticket Booking System | 28/9/2023 | 17/6/2026 | El parámetro 'age' del recurso process_registration.php no valida los caracteres recibidos y se envían sin filtrar a la base de datos. | |
| Modificada | Crítica (9.8) | 0.98% | — | Projectworlds Online Movie Ticket Booking System | 28/9/2023 | 17/6/2026 | El parámetro 'Email' del recurso process_login.php no valida los caracteres recibidos y se envían sin filtrar a la base de datos. | |
| Modificada | Crítica (9.8) | 0.98% | — | Projectworlds Online Movie Ticket Booking System | 28/9/2023 | 17/6/2026 | El parámetro 'search' del recurso process_search.php no valida los caracteres recibidos y se envían sin filtrar a la base de datos. | |
| Modificada | Media (5.4) | 0.40% | — | Projectworlds Online Movie Ticket Booking System | 28/9/2023 | 17/6/2026 | El Online Movie Ticket Booking System v1.0 es vulnerable a una vulnerabilidad de Cross-Site Scripting reflejado autenticado. | |
| Modificada | Media (6.1) | 0.37% | — | Vcita Online Booking & Scheduling Calendar | 4/9/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad de Cross-Site Scripting (XSS) reflejado no autenticado en el plugin vCita.Com Online Booking & Scheduling Calendar para WordPress de vcita en versiones anteriores e incluyendo la 4.3.2. | |
| Modificada | Media (6.1) | 0.39% | — | Saasproject Booking Package | 4/9/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento SAASPROJECT Booking Package Booking Package versiones <= 1.6.01 | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Event Booking Calendar | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpjabbers Taxi Booking Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Hotel Booking System | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Restaurant Booking Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.1) | 0.38% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 24/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Bookingultrapro Appointments Booking Calendar | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions. | |
| Modificada | Alta (8.8) | 0.82% | — | Oplugins Booking Manager | 16/8/2023 | 17/6/2026 | The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | Availability Booking Calendar 5.0 de PHPJabbers es vulnerable a la toma de control de cuentas de usuario mediante el cambio de nombre de usuario/contraseña. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | Availability Booking Calendar 5.0 de PHP Jabbers es vulnerable al Control de Acceso Incorrecto. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | Availability Booking Calendar 5.0 de PHPJabbers es vulnerable a un Control de Acceso Incorrecto debido a una incorrecta validación de entrada del parámetro de contraseña. | |
| Modificada | Media (6.1) | 3.1% | 💥 Exploit | Phpjabbers Rental Property Booking Calendar | 3/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this… | |
| Modificada | Media (6.1) | 8.4% | 💥 Exploit | Phpjabbers Taxi Booking Script | 3/8/2023 | 17/6/2026 | A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The associated identifier of this… | |
| Modificada | Media (6.1) | 8.3% | 💥 Exploit | Phpjabbers Night Club Booking Software | 3/8/2023 | 17/6/2026 | A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was… | |
| Modificada | Media (6.1) | 8.4% | 💥 Exploit | Phpjabbers Service Booking Script | 3/8/2023 | 17/6/2026 | A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is… | |
| Modificada | Media (6.1) | 8.4% | 💥 Exploit | Phpjabbers Shuttle Booking Software | 3/8/2023 | 17/6/2026 | A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is… | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Phpjabbers Availability Booking Calendar | 3/8/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en PHP Jabbers Availability Booking Calendar v5.0 y se ha clasificado como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo "/index.php". La manipulación del argumento "session_id" conduce a Cross-Site Scripting (XSS). El ataque puede lanzarse de… |