Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.72%—Phpgurukul Restaurant Table Booking System25/12/202317/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/bwdates-report-details.php. The manipulation of the argument fdate/tdate leads to sql injection. It is possible to launch the attack remotely. The exploit…
ModificadaMedia (5.4)0.38%—10to8 Sign IN Scheduling Online Appointment Booking System14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10to8 Sign In Scheduling Online Appointment Booking System allows Stored XSS.This issue affects Sign In Scheduling Online Appointment Booking System: from n/a through 1.0.9.
ModificadaAlta (7.5)0.66%—Phpgurukul Restaurant Table Booking System1/12/202317/6/2026
Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.
ModificadaAlta (7.5)0.96%—Phpgurukul Restaurant Table Booking System10/11/202317/6/2026
A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file booking-details.php of the component Reservation Status Handler. The manipulation of the argument bid leads to information disclosure. The attack…
ModificadaMedia (6.1)0.49%—Phpgurukul Restaurant Table Booking System10/11/202317/6/2026
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file index.php of the component Reservation Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of…
ModificadaCrítica (9.8)0.70%—Phpgurukul Restaurant Table Booking System10/11/202317/6/2026
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated…
ModificadaCrítica (9.8)0.70%—Online BUS Booking System Project Online BUS Booking System2/11/202317/6/2026
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.70%—Online BUS Booking System Project Online BUS Booking System2/11/202317/6/2026
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.70%—Online BUS Booking System Project Online BUS Booking System2/11/202317/6/2026
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Online BUS Booking System Project Online BUS Booking System2/11/202317/6/2026
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaAlta (8.8)0.21%—Pinpoint Booking System13/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.
ModificadaAlta (8.8)0.27%—Checkfront Online Booking System6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Checkfront Inc. Checkfront Online Booking System plugin <= 3.6 versions.
ModificadaMedia (6.1)0.39%—Anujk305 Online Banquet Booking System30/9/202317/6/2026
A vulnerability was found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /mail.php of the component Contact Us Page. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The…
ModificadaMedia (6.1)0.39%—Anujk305 Online Banquet Booking System30/9/202317/6/2026
A vulnerability has been found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /book-services.php of the component Service Booking. The manipulation of the argument message leads to cross site scripting. The attack can be…
ModificadaMedia (6.1)0.39%—Phpgurukul Online Banquet Booking System30/9/202317/6/2026
A vulnerability, which was classified as problematic, was found in Online Banquet Booking System 1.0. Affected is an unknown function of the file /view-booking-detail.php of the component Account Detail Handler. The manipulation of the argument username leads to cross site scripting. It is possible to launch the…
ModificadaMedia (5.4)0.41%—Projectworlds Online Movie Ticket Booking System28/9/202317/6/2026
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.
ModificadaCrítica (9.8)0.98%—Projectworlds Online Movie Ticket Booking System28/9/202317/6/2026
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.98%—Projectworlds Online Movie Ticket Booking System28/9/202317/6/2026
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.98%—Projectworlds Online Movie Ticket Booking System28/9/202317/6/2026
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaMedia (5.4)0.40%—Projectworlds Online Movie Ticket Booking System28/9/202317/6/2026
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.
ModificadaCrítica (9.8)0.89%—Phpjabbers Hotel Booking System28/8/202317/6/2026
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)0.52%—Gzscripts GZ Multi Hotel Booking System10/7/202317/6/2026
A vulnerability was found in GZ Scripts GZ Multi Hotel Booking System 1.8. It has been classified as problematic. Affected is an unknown function of the file /index.php. The manipulation of the argument adults/children/cal_id leads to cross site scripting. It is possible to launch the attack remotely. VDB-233358 is…
ModificadaMedia (4.3)0.30%—Salonbookingsystem Salon Booking System28/6/202317/6/2026
The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on the 'save_customer' function. This makes it possible for unauthenticated attackers to change the admin role to customer or change…
ModificadaMedia (4.8)0.39%—Wpbookingsystem WP Booking System7/4/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.
ModificadaMedia (4.8)0.51%—Pinpoint Booking System6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.2.8 versions.
Orbitaley — Vulnerabilidades