Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.40% | — | Facebook-kimmymatillano Point OF Sale System | 7/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dymanic_table.php. Such manipulation of the argument scripts leads to cross site scripting. The attack may be… | |
| Analizada | Baja (2.1) | 0.40% | — | Facebook-kimmymatillano Point OF Sale System | 7/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_th.php. This manipulation of the argument scripts causes cross site scripting. The attack is possible to be carried out remotely.… | |
| Analizada | Baja (2.1) | 0.40% | — | Facebook-kimmymatillano Point OF Sale System | 7/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts results in cross site scripting. The attack can be… | |
| Analizada | Baja (2.1) | 0.40% | — | Facebook-kimmymatillano Point OF Sale System | 7/9/2025 | 30/9/2026 | A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Performing manipulation of the argument scripts results in cross site scripting. It is possible to initiate the… | |
| Analizada | Baja (2.1) | 0.40% | — | Facebook-kimmymatillano Point OF Sale System | 6/9/2025 | 30/9/2026 | A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site scripting. Remote exploitation of the attack is… | |
| Analizada | Baja (2) | 0.29% | — | Facebook-kimmymatillano Point OF Sale System | 6/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation of the argument scripts results in cross site scripting. The attack may be… | |
| Analizada | Baja (2) | 0.29% | — | Facebook-kimmymatillano Point OF Sale System | 6/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit is publicly… | |
| Analizada | Baja (2) | 0.30% | — | Facebook-kimmymatillano Point OF Sale System | 5/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts causes cross site scripting. The attack can be initiated remotely.… | |
| Analizada | Baja (2) | 0.29% | — | Facebook-kimmymatillano Point OF Sale System | 5/9/2025 | 17/6/2026 | A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument scripts results in cross site scripting. It is possible to… | |
| Analizada | Media (5.5) | 0.41% | — | Facebook-julykringcadayona Student Information System | 30/8/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (6.1) | 0.22% | — | Shopfiles Ebook Store | 16/8/2025 | 17/6/2026 | The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers. | |
| Aplazada | Media (4.3) | 0.13% | — | Shopfiles Ebook StoreAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.This issue affects Ebook Store: from n/a through <= 5.8013. | |
| Aplazada | Alta (7.3) | 0.27% | — | Vonstroheim ThebookingAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects TheBooking: from n/a through <= 1.4.4. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Shopfiles Ebook StoreAI | 24/7/2025 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may… | |
| Aplazada | Media (4.4) | 0.23% | — | Shopfiles Ebook StoreAI | 21/7/2025 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions up to, and including, 5.8012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web… | |
| Aplazada | Alta (8.1) | 0.31% | — | Facebook MvfstAI | 11/7/2025 | 17/6/2026 | A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00. | |
| Analizada | Crítica (9.8) | 0.69% | 💥 PoC | Ptoffice PT Project Notebooks | 28/6/2025 | 17/6/2026 | The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. | |
| Aplazada | Media (5.9) | 0.20% | — | Shopfiles Ebook StoreAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows Stored XSS.This issue affects Ebook Store: from n/a through <= 5.8008. | |
| Aplazada | Media (6.5) | 0.26% | — | Shopfiles Ebook StoreAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows DOM-Based XSS.This issue affects Ebook Store: from n/a through <= 5.8009. | |
| Modificada | Media (4.3) | 0.17% | — | Themetechmount Truebooker | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.1) | 0.14% | — | Infoway Ebook DownloaderAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Request Forgery.This issue affects Ebook Downloader: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Infoway Ebook DownloaderAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Stored XSS.This issue affects Ebook Downloader: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.29% | — | Simplebooklet PDF Viewer AND EmbedderAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simplebooklet Simplebooklet PDF Viewer and Embedder simplebooklet allows Stored XSS.This issue affects Simplebooklet PDF Viewer and Embedder: from n/a through <= 1.1.1. | |
| Analizada | Media (6.8) | 0.37% | 💥 PoC | Facebook Below | 11/3/2025 | 17/6/2026 | A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow. | |
| Modificada | Media (5.4) | 0.25% | — | Simplebooklet | 18/2/2025 | 17/6/2026 | The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simplebooklet' shortcode in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |