Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.25% | — | Codeastro Online Movie Ticket Booking System | 7/7/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this issue is some unknown functionality of the file /check-status.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The… | |
| Analizada | Baja (1.9) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-table.php. The manipulation of the argument tableno leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Analizada | Baja (1.9) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/manage-subadmins.php. The manipulation of the argument fullname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Baja (1.9) | 0.30% | — | Phpgurukul Restaurant Table Booking System | 10/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.48% | — | Phpgurukul Restaurant Table Booking System | 23/5/2025 | 17/6/2026 | PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php. | |
| Aplazada | Media (5.4) | 0.14% | — | Salonbookingsystem Salon Booking SystemAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16. | |
| Aplazada | Media (4.3) | 0.23% | — | Quanticalabs CAR Park Booking SystemAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress car-park-booking-system-for-wordpress.This issue affects Car Park Booking System for WordPress: from n/a through <= 2.6. | |
| Analizada | Media (4.8) | 0.26% | — | Salonbookingsystem Salon Booking System | 15/5/2025 | 17/6/2026 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Boat Booking System | 1/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The manipulation of the argument Status leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Boat Booking System | 1/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.46% | — | Phpgurukul Boat Booking System | 1/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The manipulation of the argument bid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (4.8) | 0.37% | — | Fabian Simple Movie Ticket Booking System | 29/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation of the argument prize leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to… | |
| Analizada | Media (4.8) | 0.35% | — | Fabian Theater Seat Booking System | 29/4/2025 | 17/6/2026 | A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The manipulation of the argument cancelcustomername leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit… | |
| Modificada | Crítica (9.8) | 0.78% | — | Phpgurukul Online Banquet Booking System | 28/4/2025 | 5/7/2026 | An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component | |
| Analizada | Media (5) | 0.26% | — | Codeastro BUS Ticket Booking System | 28/4/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing. | |
| Analizada | Crítica (9.8) | 0.54% | — | Codeastro BUS Ticket Booking System | 25/4/2025 | 17/6/2026 | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder. | |
| Analizada | Alta (8) | 0.27% | — | Codeastro BUS Ticket Booking System | 24/4/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks. | |
| Aplazada | Alta (8.8) | 0.59% | — | Turitop Booking SystemAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in TuriTop TuriTop Booking System turitop-booking-system allows Object Injection.This issue affects TuriTop Booking System: from n/a through <= 1.0.10. | |
| Aplazada | Alta (7.1) | 0.29% | — | Commotion Course Booking SystemAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ComMotion Course Booking System course-booking-system allows Reflected XSS.This issue affects Course Booking System: from n/a through <= 6.1.2. | |
| Analizada | Media (4.8) | 0.34% | — | Razormist Simple Hotel Booking System | 16/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability affects the function Login. The manipulation of the argument uname leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may… | |
| Aplazada | Media (5.3) | 0.63% | — | Comotion Course Booking SystemAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Course Booking System: from n/a through <= 6.1. | |
| Modificada | Alta (8.8) | 0.52% | — | Salonbookingsystem Salon Booking System | 4/4/2025 | 5/10/2026 | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | |
| Analizada | Media (5.1) | 0.47% | — | Phpgurukul Restaurant Table Booking System | 4/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /edit-subadmin.php. The manipulation of the argument fullname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.47% | — | Phpgurukul Restaurant Table Booking System | 4/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit has been… |