Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.36% | — | Fabian Train Ticket Reservation System | 17/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0. This affects an unknown part of the component Login Form. The manipulation of the argument username leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.64% | — | Code-projects Cinema Seat Reservation System | 9/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/deleteBooking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (4.3) | 0.18% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.4.3. | |
| Aplazada | Alta (7.3) | 0.52% | — | Redi Restaurant ReservationAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211. | |
| Analizada | Media (6.1) | 0.32% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 20/11/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.8) | 0.26% | — | Homeserve | 8/11/2024 | 5/7/2026 | An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function. | |
| Aplazada | Media (5.4) | 0.30% | — | Redi Restaurant ReservationAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422. | |
| Analizada | Media (5.3) | 0.32% | — | Klokantech Maptiler Tileserver GL | 30/10/2024 | 17/6/2026 | A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation of the argument key leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.53% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload of the file /guest/update.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.44% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/mod_room/controller.php. The manipulation of the argument id leads to sql injection. It… | |
| Analizada | Media (5.3) | 1.2% | 💥 PoC | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely.… | |
| Aplazada | Alta (7.1) | 0.27% | — | Rconnect305 Restaurant Reservations WidgetAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restaurant Reservations Widget restaurantconnect-reswidget allows Reflected XSS.This issue affects Restaurant Reservations Widget: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.39% | — | Redi Restaurant ReservationAI | 17/10/2024 | 17/6/2026 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.9) | 0.70% | — | Code-projects Restaurant Reservation System | 10/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.59% | — | Code-projects Restaurant Reservation System | 2/10/2024 | 17/6/2026 | A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter2.php. The manipulation of the argument from/to leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.80% | — | Code-projects Restaurant Reservation System | 1/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.80% | — | Code-projects Restaurant Reservation System | 1/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.61% | — | Oretnom23 Railway Reservation System | 29/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper access controls. The attack may be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.62% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulnerability affects unknown code of the file contact_us.php of the component Message Us Form. The manipulation of the argument fullname/email/message leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.48% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /?page=tickets of the component Ticket Handler. The manipulation of the argument id leads to improper access controls. The attack may be… | |
| Analizada | Media (5.3) | 0.44% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument page with the input trains/schedules/system_info leads to improper authorization. The… | |
| Aplazada | Alta (8.8) | 0.42% | — | Exnet Informatics Ferry Reservation SystemAI | 23/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS. This issue affects Ferry Reservation System: before 240805-002. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Exnet Informatics Software Ferry Reservation SystemAI | 23/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection. This issue affects Ferry Reservation System: before 240805-002. | |
| Analizada | Media (5.3) | 0.57% | — | Code-projects Restaurant Reservation System | 22/9/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… |