Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

2553 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.19%—Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+8323/8/202317/6/2026
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
ModificadaMedia (6.1)0.38%—Bookingultrapro Appointments Booking Calendar23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.
ModificadaMedia (6.7)0.19%—Lenovo 13W Yoga FirmwareLenovo 13W Yoga GEN 2 FirmwareLenovo Ideapad 1-11ada05 FirmwareLenovo Ideapad 1-11igl05 Firmware+2517/8/202317/6/2026
Se ha identificado un desbordamiento de búfer en el controlador SystemUserMasterHddPwdDxe de algunos productos portátiles de Lenovo que puede permitir a un atacante con acceso local y privilegios elevados ejecutar código arbitrario.
ModificadaMedia (6.7)0.19%—Lenovo Legion 5 PRO 16iah7h FirmwareLenovo Legion 5 PRO 16iah7 FirmwareLenovo Legion 5 PRO 16arh7 FirmwareLenovo Legion 5 PRO 16arh7h Firmware+2617/8/202317/6/2026
Se ha identificado un desbordamiento de búfer en el controlador SetupUtility de algunos productos portátiles de Lenovo los cuales podrían permitir a un atacante con acceso local y privilegios elevados ejecutar código arbitrario.
ModificadaAlta (8.8)0.82%—Oplugins Booking Manager16/8/202317/6/2026
The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.
ModificadaAlta (7.8)0.19%—Samsung Galaxy Book GO FirmwareSamsung Galaxy Book GO 5G FirmwareSamsung Galaxy Book2 GO FirmwareSamsung Galaxy Book2 PRO 360 Firmware10/8/202317/6/2026
Stack overflow vulnerability in SSHDCPAPP TA prior to &quot;SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023&quot; in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Galaxy Book GO FirmwareSamsung Galaxy Book GO 5G FirmwareSamsung Galaxy Book2 GO FirmwareSamsung Galaxy Book2 PRO 360 Firmware10/8/202317/6/2026
Una vulnerabilidad de escritura fuera de límites en SSHDCPAPP TA antes de "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" en Windows Update para Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go y Galaxy book2 Pro 360 permite a un atacante local ejecutar código arbitrario.
ModificadaCrítica (9.8)0.89%—Phpjabbers Availability Booking Calendar4/8/202317/6/2026
Availability Booking Calendar 5.0 de PHPJabbers es vulnerable a la toma de control de cuentas de usuario mediante el cambio de nombre de usuario/contraseña.
ModificadaCrítica (9.8)0.89%—Phpjabbers Availability Booking Calendar4/8/202317/6/2026
Availability Booking Calendar 5.0 de PHP Jabbers es vulnerable al Control de Acceso Incorrecto.
ModificadaCrítica (9.8)0.89%—Phpjabbers Availability Booking Calendar4/8/202317/6/2026
Availability Booking Calendar 5.0 de PHPJabbers es vulnerable a un Control de Acceso Incorrecto debido a una incorrecta validación de entrada del parámetro de contraseña.
ModificadaMedia (6.1)3.1%💥 ExploitPhpjabbers Rental Property Booking Calendar3/8/202317/6/2026
A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this…
ModificadaMedia (6.1)8.4%💥 ExploitPhpjabbers Taxi Booking Script3/8/202317/6/2026
A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The associated identifier of this…
ModificadaMedia (6.1)8.3%💥 ExploitPhpjabbers Night Club Booking Software3/8/202317/6/2026
A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was…
ModificadaMedia (6.1)8.4%💥 ExploitPhpjabbers Service Booking Script3/8/202317/6/2026
A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is…
ModificadaMedia (6.1)8.4%💥 ExploitPhpjabbers Shuttle Booking Software3/8/202317/6/2026
A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is…
ModificadaMedia (6.1)1.8%💥 ExploitPhpjabbers Availability Booking Calendar3/8/202317/6/2026
Se ha encontrado una vulnerabilidad en PHP Jabbers Availability Booking Calendar v5.0 y se ha clasificado como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo "/index.php". La manipulación del argumento "session_id" conduce a Cross-Site Scripting (XSS). El ataque puede lanzarse de…
ModificadaMedia (6.1)0.43%—Mage-people BUS Ticket Booking With Seat Reservation2/8/202317/6/2026
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
ModificadaMedia (6.1)0.50%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
Existe una vulnerabilidad de Cross Site Scripting (XSS) en el parámetro "theme" de preview.php en Time Slots Booking Calendar v3.3 de PHPJabbers.
ModificadaAlta (8.8)0.76%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
En Time Slots Booking Calendar 3.3 de PHP Jabbers, la falta de verificación al cambiar una dirección de correo electrónico y/o contraseña (en la Página de Perfil) permite a atacantes remotos tomar el control de cuentas.
ModificadaCrítica (9.8)0.77%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
La enumeración de usuarios se encuentra en Time Slots Booking Calendar v3.3 de PHPJabbers. Este problema se produce durante la recuperación de contraseñas, donde una diferencia en los mensajes podría permitir a un atacante determinar si el usuario es válido o no, permitiendo un ataque de fuerza bruta con usuarios…
ModificadaCrítica (9.8)0.99%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
La validación incorrecta del parámetro de contraseña en Time Slots Booking Calendar v 3.3 de PHPJabbers resulta en contraseñas inseguras.
ModificadaMedia (6.1)0.50%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
Existe una vulnerabilidad de Cross Site Scripting (XSS) en el parámetro "cid" de preview.php en Time Slots Booking Calendar v3.3 de PHPJabbers.
ModificadaMedia (5.4)0.56%—Gzscripts Availability Booking Calendar PHP27/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible…
ModificadaMedia (5.4)0.56%—Gzscripts Availability Booking Calendar PHP27/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The…
ModificadaMedia (6.1)0.41%—Booking Calendar Project Booking Calendar18/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.