Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.85%—Salonbookingsystem Salon Booking System19/6/202417/6/2026
The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible for unauthenticated attackers to upload…
ModificadaMedia (5.4)0.39%—Salonbookingsystem Salon Booking System8/6/202417/6/2026
The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admin_init in all versions up to, and including, 9.9. This makes it possible for authenticated attackers with subscriber access or higher to…
AplazadaMedia (6.5)0.40%—Pinpoint Booking SystemAI4/6/202417/6/2026
External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.
AnalizadaMedia (5.1)0.52%—Oretnom23 Online CAR Wash Booking System27/5/202417/6/2026
A vulnerability, which was classified as problematic, has been found in oretnom23 Online Car Wash Booking System 1.0. This issue affects some unknown processing of the file /admin/?page=user/list. The manipulation of the argument First Name/Last Name with the input <script>confirm (document.cookie)</script> leads to…
ModificadaCrítica (9.1)1.2%—Salonbookingsystem Salon Booking System21/5/202417/6/2026
The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files,…
AplazadaAlta (8.2)0.36%—Quanticalabs Chauffeur Taxi Booking SystemAI17/5/202417/6/2026
Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.
AnalizadaAlta (7.2)0.52%—Salonbookingsystem Salon Booking System17/5/202417/6/2026
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.
AnalizadaMedia (6.3)0.46%—Salonbookingsystem Salon Booking System26/4/202417/6/2026
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the…
AnalizadaMedia (4.8)0.42%—Salonbookingsystem Salon Booking System26/4/202417/6/2026
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (4.3)0.25%—Salonbookingsystem Salon Booking System26/4/202417/6/2026
The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (4.7)0.46%—Salonbookingsystem Salon Booking System17/4/202417/6/2026
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'sms_prefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the…
AnalizadaMedia (5.7)0.63%—Salonbookingsystem Salon Booking System17/4/202417/6/2026
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed…
AplazadaCrítica (10)0.63%—Quanticalabs Chauffeur Taxi Booking SystemAI31/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 7.2.
ModificadaCrítica (9.8)0.67%—Salonbookingsystem Salon Booking System29/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.
AnalizadaMedia (6.5)0.60%—Campcodes Complete Online DJ Booking System21/3/202417/6/2026
A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. Affected is an unknown function of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (6.5)0.60%—Campcodes Complete Online DJ Booking System21/3/202417/6/2026
A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. This issue affects some unknown processing of the file /admin/user-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (6.1)0.57%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability classified as problematic was found in Campcodes Complete Online DJ Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to cross site scripting. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.1)0.51%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability classified as problematic has been found in Campcodes Complete Online DJ Booking System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (6.1)0.51%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/booking-bwdates-reports-details.php. The manipulation of the argument fromdate leads to cross site scripting. The attack may be initiated…
AnalizadaMedia (6.1)0.51%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remotely. The exploit…
AnalizadaMedia (6.1)0.54%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/contactus.php. The manipulation of the argument email leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (6.1)0.54%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/user-search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The…
AnalizadaMedia (6.5)0.50%—Campcodes Complete Online DJ Booking System20/3/202417/6/2026
A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/booking-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched…
ModificadaMedia (5.4)0.53%—Vehicle Booking System Project Vehicle Booking System9/1/202417/6/2026
A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of the component Feedback Page. The manipulation of the argument My Testemonial leads to cross site scripting. The attack can be initiated…
ModificadaMedia (6.1)0.63%—Vehicle Booking System Project Vehicle Booking System9/1/202417/6/2026
A vulnerability, which was classified as problematic, was found in CodeAstro Vehicle Booking System 1.0. This affects an unknown part of the file usr/usr-register.php of the component User Registration. The manipulation of the argument Full_Name/Last_Name/Address with the input <script>alert(document.cookie)</script>…
Orbitaley — Vulnerabilidades