Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.49% | — | Fabian Simple Online Hotel Reservation System | 21/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Online Hotel Reservation System | 20/6/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.1) | 0.36% | — | Sscms Siteserver CMS | 27/5/2025 | 17/6/2026 | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor. | |
| Aplazada | Alta (7.1) | 0.22% | — | Catkin Redi-restaurant-reservationAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation redi-restaurant-reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through <= 24.1209. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Smartcms BUS Ticket Booking With Seat ReservationAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticket Booking with Seat Reservation for WooCommerce scw-bus-seat-reservation allows SQL Injection.This issue affects Bus Ticket Booking with Seat Reservation for WooCommerce: from n/a through <= 1.7. | |
| Analizada | Media (4.8) | 0.37% | — | Fabian Simple BUS Reservation System | 10/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has… | |
| Analizada | Media (5.3) | 0.53% | — | Fabian Online BUS Reservation System | 3/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This affects an unknown part of the file /seatlocation.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.53% | — | Fabian Online BUS Reservation System | 3/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Affected by this issue is some unknown functionality of the file /print.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.41% | — | Smartcmsmarket Advance Seat Reservation Management FOR Woocommerce | 2/5/2025 | 17/6/2026 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'profileId' parameter in all versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (4.8) | 0.32% | — | Fabian Train Ticket Reservation System | 28/4/2025 | 17/6/2026 | A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is the function Reservation of the component Ticket Reservation. The manipulation of the argument Name leads to stack-based buffer overflow. Attacking locally is a… | |
| Modificada | Alta (8.8) | 0.15% | — | E4jconnect Vikrestaurants Table Reservations AND Take-away | 22/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forgery.This issue affects VikRestaurants: from n/a through <= 1.3.3. | |
| Analizada | Crítica (9.1) | 0.35% | — | Honor Phoneservice | 17/4/2025 | 17/6/2026 | Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity. | |
| Analizada | Media (6.5) | 0.51% | — | Oracle Teleservice | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks… | |
| Analizada | Media (4.8) | 0.24% | — | Fabian BUS Reservation System | 3/4/2025 | 17/6/2026 | A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue is the function Login of the component Login Form. The manipulation of the argument Str1 leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been… | |
| Aplazada | Media (6.5) | 0.36% | — | Xtreeme Planyo Online Reservation SystemAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system planyo-online-reservation-system allows Stored XSS.This issue affects Planyo online reservation system: from n/a through <= 3.1. | |
| Aplazada | Media (4.9) | 0.62% | — | Rustaurius Five Star Restaurant ReservationsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29. | |
| Modificada | Media (4.8) | 0.89% | 💥 Exploit | Reservit Hotel | 7/3/2025 | 17/6/2026 | The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.3) | 0.50% | — | Fabian Online Ticket Reservation System | 7/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /passenger.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (4.7) | 0.30% | — | Ataksapp Reservation Management SystemAI | 6/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS). This issue affects Reservation Management System: before 4.2.3. | |
| Modificada | Alta (8.8) | 0.70% | — | Phpjabbers BUS Reservation System | 20/2/2025 | 17/6/2026 | PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers BUS Reservation System | 20/2/2025 | 17/6/2026 | PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters. | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers BUS Reservation System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Analizada | Media (5.3) | 0.38% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file select-menu.php. The manipulation of the argument table leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.52% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/approve-reject.php. The manipulation of the argument breject_id leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.4) | 0.33% | — | Alex Reservations Smart Restaurant BookingAI | 30/1/2025 | 17/6/2026 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |