Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

2553 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)6.9%💥 ExploitAN Gradebook Project AN Gradebook17/7/202317/6/2026
The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber
ModificadaMedia (4.3)0.39%—Thimpress WP Hotel Booking12/7/202317/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request…
ModificadaMedia (6.1)0.52%—Gzscripts GZ Multi Hotel Booking System10/7/202317/6/2026
A vulnerability was found in GZ Scripts GZ Multi Hotel Booking System 1.8. It has been classified as problematic. Affected is an unknown function of the file /index.php. The manipulation of the argument adults/children/cal_id leads to cross site scripting. It is possible to launch the attack remotely. VDB-233358 is…
ModificadaMedia (6.1)0.51%—Gzscripts PHP GZ Hotel Booking Script10/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in GZ Scripts PHP GZ Hotel Booking Script 1.8. This affects an unknown part of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to initiate the attack…
ModificadaMedia (6.1)0.38%—Gzscripts Ticket Booking Script10/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in GZ Scripts Ticket Booking Script 1.8. Affected by this issue is some unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack may be…
ModificadaMedia (5.4)0.51%—Gzscripts Event Booking Calendar10/7/202317/6/2026
A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaMedia (4.8)0.54%—AN Gradebook Project AN Gradebook10/7/202317/6/2026
The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (6.1)0.39%—Gzscripts Time Slot Booking Calendar PHP7/7/202317/6/2026
A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated…
ModificadaMedia (6.1)0.39%—Gzscripts Availability Booking Calendar PHP7/7/202317/6/2026
A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site…
ModificadaMedia (6.1)0.39%—Simplephpscripts Guestbook Script30/6/202317/6/2026
Se ha encontrado una vulnerabilidad en SimplePHPscripts GuestBook Script v2.2. Se ha clasificado como problemática. Esto afecta a una parte desconocida del archivo "preview.php" del componente "URL Parameter Handler". La manipulación conduce a Cross-Site Scripting (XSS). Es posible iniciar el ataque de forma remota.…
ModificadaCrítica (9.8)1.9%—Stylemixthemes Bookit30/6/202317/6/2026
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on…
ModificadaMedia (4.3)0.30%—Salonbookingsystem Salon Booking System28/6/202317/6/2026
The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on the 'save_customer' function. This makes it possible for unauthenticated attackers to change the admin role to customer or change…
ModificadaMedia (4.8)0.44%—Magepeople Booking & Rental Manager23/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.
ModificadaCrítica (9.8)0.98%—Livebook22/6/202317/6/2026
Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine. Any user using Livebook Desktop on Windows is potentially vulnerable to…
ModificadaAlta (7.8)0.23%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7.8)0.20%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7.8)0.23%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7)0.14%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+28714/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7)0.17%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+28714/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7)0.17%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+28714/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.