Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.52% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/approve-reject.php. The manipulation of the argument breject_id leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.4) | 0.33% | — | Alex Reservations Smart Restaurant BookingAI | 30/1/2025 | 17/6/2026 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (4.8) | 0.36% | — | Fabian Train Ticket Reservation System | 17/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0. This affects an unknown part of the component Login Form. The manipulation of the argument username leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.64% | — | Code-projects Cinema Seat Reservation System | 9/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/deleteBooking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (4.3) | 0.18% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.4.3. | |
| Aplazada | Alta (7.3) | 0.52% | — | Redi Restaurant ReservationAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211. | |
| Analizada | Media (6.1) | 0.32% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 20/11/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.30% | — | Redi Restaurant ReservationAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422. | |
| Analizada | Media (5.3) | 0.53% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload of the file /guest/update.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.44% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/mod_room/controller.php. The manipulation of the argument id leads to sql injection. It… | |
| Analizada | Media (5.3) | 1.2% | 💥 PoC | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely.… | |
| Aplazada | Alta (7.1) | 0.27% | — | Rconnect305 Restaurant Reservations WidgetAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restaurant Reservations Widget restaurantconnect-reswidget allows Reflected XSS.This issue affects Restaurant Reservations Widget: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.39% | — | Redi Restaurant ReservationAI | 17/10/2024 | 17/6/2026 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.9) | 0.70% | — | Code-projects Restaurant Reservation System | 10/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.59% | — | Code-projects Restaurant Reservation System | 2/10/2024 | 17/6/2026 | A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter2.php. The manipulation of the argument from/to leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.80% | — | Code-projects Restaurant Reservation System | 1/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.80% | — | Code-projects Restaurant Reservation System | 1/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.61% | — | Oretnom23 Railway Reservation System | 29/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper access controls. The attack may be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.62% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulnerability affects unknown code of the file contact_us.php of the component Message Us Form. The manipulation of the argument fullname/email/message leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.48% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /?page=tickets of the component Ticket Handler. The manipulation of the argument id leads to improper access controls. The attack may be… | |
| Analizada | Media (5.3) | 0.44% | — | Oretnom23 Railway Reservation System | 28/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument page with the input trains/schedules/system_info leads to improper authorization. The… | |
| Aplazada | Alta (8.8) | 0.42% | — | Exnet Informatics Ferry Reservation SystemAI | 23/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS. This issue affects Ferry Reservation System: before 240805-002. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Exnet Informatics Software Ferry Reservation SystemAI | 23/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection. This issue affects Ferry Reservation System: before 240805-002. | |
| Analizada | Media (5.3) | 0.57% | — | Code-projects Restaurant Reservation System | 22/9/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… |