Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.49%💥 PoCPhpjabbers Limo Booking Software12/10/202317/6/2026
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
ModificadaAlta (7.5)0.59%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)0.38%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
ModificadaAlta (7.5)0.67%—Phpjabbers PHP Shopping Cart21/9/202317/6/2026
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
ModificadaMedia (4.3)0.89%—Cisco Jabber15/9/202317/6/2026
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP…
ModificadaCrítica (9.8)0.53%—Phpjabbers Cleaning Business Software11/9/202317/6/2026
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
ModificadaAlta (7.5)0.67%—Phpjabbers Business Directory Script30/8/202317/6/2026
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
ModificadaMedia (6.1)1.1%💥 ExploitPhpjabbers PHP Forum Script30/8/202317/6/2026
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
ModificadaMedia (6.1)0.43%—Phpjabbers Business Directory Script30/8/202317/6/2026
phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
ModificadaCrítica (9.8)0.89%—Phpjabbers Make AN Offer Widget28/8/202317/6/2026
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Ticket Support Script28/8/202317/6/2026
User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Event Booking Calendar28/8/202317/6/2026
User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers CAR Rental Script28/8/202317/6/2026
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)1.1%—Phpjabbers Taxi Booking Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Fundraising Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Yacht Listing Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Hotel Booking System28/8/202317/6/2026
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Restaurant Booking Script28/8/202317/6/2026
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Document Creator28/8/202317/6/2026
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Food Delivery Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Callback Widget28/8/202317/6/2026
User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)1.3%💥 ExploitPhpjabbers Callback Widget28/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.
ModificadaAlta (8.8)0.96%—Phpjabbers CAR Rental Script28/8/202317/6/2026
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
ModificadaMedia (5.4)1.1%💥 ExploitPhpjabbers Ticket Support Script28/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.
ModificadaMedia (6.1)1.0%💥 ExploitPhpjabbers Make AN Offer Widget28/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.
Orbitaley — Vulnerabilidades