Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2553 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.53% | — | Facebook Hhvm | 10/5/2023 | 17/6/2026 | HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call… | |
| Modificada | Alta (8.8) | 0.87% | — | Avirato Hotels Online Booking Engine | 8/5/2023 | 17/6/2026 | The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks. | |
| Modificada | Media (6.1) | 0.40% | — | Facebook Lexical | 29/4/2023 | 17/6/2026 | Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources. | |
| Modificada | Media (5.5) | 0.18% | — | HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+87 | 28/4/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Media (6.5) | 0.56% | — | WP Fevents Book Project WP Fevents Book | 24/4/2023 | 17/6/2026 | The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users. | |
| Modificada | Media (5.4) | 0.44% | — | WP Fevents Book Project WP Fevents Book | 24/4/2023 | 17/6/2026 | The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.47% | — | Bestwebsoft Facebook Button | 10/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.34… | |
| Modificada | Alta (8.8) | 0.35% | — | Bestwebsoft Facebook Button | 10/4/2023 | 16/6/2026 | A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The… | |
| Modificada | Media (4.8) | 0.39% | — | Wpbookingsystem WP Booking System | 7/4/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions. | |
| Modificada | Media (6.1) | 0.36% | — | Simple Guestbook Management System Project Simple Guestbook Management System | 6/4/2023 | 9/7/2026 | Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments. | |
| Modificada | Media (4.8) | 0.51% | — | Pinpoint Booking System | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.2.8 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Codepeople WP Time Slots Booking Form | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 5/4/2023 | 17/6/2026 | The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying knowledge bases, modifying… | |
| Modificada | Alta (8.8) | 0.64% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 5/4/2023 | 17/6/2026 | The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a… | |
| Modificada | Alta (7.5) | 1.6% | — | Facebook Zstandard | 31/3/2023 | 17/6/2026 | Se encontró una vulnerabilidad en zstd v1.4.10, donde un atacante puede proporcionar una cadena vacía como argumento a la herramienta de línea de comando para provocar una saturación del búfer. | |
| Modificada | Media (5.4) | 0.38% | — | Wpdevart Booking Calendar | 29/3/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Booking-wp-plugin Bookly | 17/3/2023 | 17/6/2026 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Crítica (9.8) | 0.76% | — | Online Book Store Project Project Online Book Store Project | 16/3/2023 | 17/6/2026 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. | |
| Modificada | Alta (8.8) | 4.5% | 💥 Exploit | Agilebio Electronic LAB Notebook | 6/3/2023 | 17/6/2026 | AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. | |
| Modificada | Media (6.1) | 0.37% | — | Asosegitim Bookcites | 3/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies Book Cites allows Cross-Site Scripting (XSS). This issue affects Book Cites: before 23.01.05. | |
| Modificada | Alta (7.5) | 1.2% | — | Online Book Store Project Online Book Store | 24/2/2023 | 17/6/2026 | Una vulnerabilidad de inyección SQL en sourcecodester online-book-store 1.0 permite a atacantes remotos ver información confidencial a través del parámetro id en la URL de la aplicación. | |
| Modificada | Media (5.5) | 0.23% | — | Executablebooks Markdown-it-py | 23/2/2023 | 17/6/2026 | Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input. | |
| Modificada | Media (5.5) | 0.23% | — | Executablebooks Markdown-it-py | 22/2/2023 | 17/6/2026 | Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input. | |
| Modificada | Media (5.4) | 0.61% | — | Gsplugins GS Books Showcase | 21/2/2023 | 17/6/2026 | The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |