Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.37%—Fabian Online Product Reservation System5/1/202617/6/2026
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the…
AnalizadaMedia (5.5)0.44%—Fabian Online Product Reservation System5/1/202617/6/2026
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.5)0.43%—Fabian Online Product Reservation System4/1/202617/6/2026
A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the file /handgunner-administrator/edit.php of the component POST Parameter Handler. The manipulation of the argument prod_id/name/price/model/serial results in sql injection. The attack can be launched…
AnalizadaMedia (5.5)0.54%—Fabian Online Product Reservation System4/1/202617/6/2026
A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some unknown functionality of the file /handgunner-administrator/delete.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaBaja (2.1)0.36%—Fabian Online Product Reservation System4/1/202617/6/2026
A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /handgunner-administrator/prod.php. Executing a manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published…
ModificadaMedia (5.5)0.43%—Fabian Online Product Reservation System4/1/202617/6/2026
A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing a manipulation of the argument cat/price/name/model/serial results in sql injection. It is possible to…
AnalizadaMedia (5.5)0.43%—Fabian Online Product Reservation System4/1/202617/6/2026
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unknown function of the file /handgunner-administrator/adminlogin.php of the component Administrator Login. Such manipulation of the argument emailadd/pass leads to sql injection. The attack may be…
AplazadaCrítica (9.3)0.48%—Selea CarplateserverAI31/12/202523/9/2026
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing…
AplazadaAlta (8.5)0.15%—Selea CarplateserverAI31/12/202523/9/2026
Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute…
AplazadaMedia (5.4)0.12%—Rustaurius Five Star Restaurant ReservationsAI24/12/20257/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8.
AplazadaMedia (6.1)0.21%—Fivestarplugins Five Star Restaurant ReservationsAI21/12/202517/6/2026
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.1)0.22%—Designthemes Dt-reservation-pluginAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Reflected XSS.This issue affects Reservation Plugin: from n/a through <= 1.6.
AplazadaCrítica (9.3)0.35%—Smartcms Advance Seat Reservation Management FOR WoocommerceAI18/12/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.
AnalizadaCrítica (9.3)0.45%—Phpjabbers BUS Reservation System15/12/202517/6/2026
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.
AnalizadaCrítica (9.3)0.52%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'Selea781830' to enable configuration upload and overwrite device settings.
ModificadaAlta (8.5)0.25%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a logged-in user visits the page.
AnalizadaMedia (5.1)0.30%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
AnalizadaCrítica (9.3)2.6%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion…
AnalizadaAlta (8.7)0.47%—Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+89/12/202517/6/2026
Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage.
AnalizadaBaja (2.1)0.37%—Jkev Dental Clinic Appointment Reservation System17/11/202517/6/2026
A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
ModificadaMedia (5.5)0.39%—Fabian Simple Online Hotel Reservation System14/11/202517/6/2026
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of the argument admin_id results in sql injection. The attack is possible to be carried out remotely. The exploit is now…
AnalizadaMedia (5.5)0.44%—Fabian Simple Online Hotel Reservation System14/11/202517/6/2026
A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation of the argument room_id leads to sql injection. The attack can be executed remotely. The exploit has been disclosed…
AplazadaAlta (7.2)0.64%💥 PoCAlex Reservations Smart Restaurant BookingAI8/11/202517/6/2026
The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level…
AplazadaCrítica (9.3)0.44%—NEC Clusterpro X FOR LinuxAINEC Expresscluster X FOR LinuxAINEC Clusterpro X Singleserversafe FOR LinuxAINEC Expresscluster X Singleserversafe FOR LinuxAI7/11/202517/6/2026
CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network…
AplazadaAlta (8.8)0.46%—Scott Reilly Preserve Code FormattingAI6/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows Object Injection.This issue affects Preserve Code Formatting: from n/a through <= 4.0.1.
Orbitaley — Vulnerabilidades