Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.74%—Code-projects Restaurant Reservation System22/9/202417/6/2026
A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaMedia (4.8)0.28%—Mage-people BUS Ticket Booking With Seat Reservation17/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Stored XSS.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.3.5.
AnalizadaMedia (5.3)0.45%—Oretnom23 Resort Reservation System17/9/202417/6/2026
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_fee.php. The manipulation of the argument toview leads to cross site scripting. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.9)0.65%—Fabian Online BUS Reservation Site26/8/202417/6/2026
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaMedia (5.4)0.30%—Kjayvik BUS Ticket Reservation System23/8/202417/6/2026
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.
AnalizadaCrítica (9.8)0.69%—Kjayvik BUS Ticket Reservation System23/8/202417/6/2026
A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters.
AnalizadaCrítica (9.4)0.30%—Kjayvik BUS Ticket Reservation System23/8/202417/6/2026
Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.
AnalizadaMedia (5.4)0.44%—Kjayvik BUS Ticket Reservation System22/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the "bookingdate" parameter.
AnalizadaMedia (5.4)0.44%—Kjayvik BUS Ticket Reservation System22/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the Name, Phone, and Email parameter fields.
AnalizadaMedia (6.1)0.47%—Kjayvik BUS Ticket Reservation System22/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via scheduleDurationPHP parameter.
AnalizadaMedia (6.9)0.80%—Online Railway Reservation System Project Online Railway Reservation System18/8/202417/6/2026
A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/assets/. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.1)0.64%—Online Railway Reservation System Project Online Railway Reservation System18/8/202417/6/2026
A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/emp-profile-avatar.php of the component Profile Photo Update Handler. The manipulation leads to unrestricted upload. The attack may be…
AnalizadaMedia (5.1)1.2%💥 ExploitOnline Railway Reservation System Project Online Railway Reservation System15/8/202417/6/2026
A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin-update-employee.php of the component Update Employee Page. The manipulation of the argument emp_fname /emp_lname…
AnalizadaMedia (5.1)0.42%—Online Railway Reservation System Project Online Railway Reservation System15/8/202417/6/2026
A vulnerability, which was classified as problematic, was found in CodeAstro Online Railway Reservation System 1.0. Affected is an unknown function of the file /admin/admin-add-employee.php of the component Add Employee Page. The manipulation of the argument emp_fname /emp_lname /emp_nat_idno/emp_addr leads to cross…
AnalizadaAlta (7.5)1.2%—Vercot Serva12/8/202417/6/2026
A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
AnalizadaMedia (5.3)0.67%—Angeljudesuarez Airline Reservation System6/8/202417/6/2026
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.55%—Angeljudesuarez Airline Reservation System6/8/202417/6/2026
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file flights.php. The manipulation of the argument departure_airport_id leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.66%—Angeljudesuarez Airline Reservation System6/8/202417/6/2026
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack…
AnalizadaMedia (5.3)0.65%—Angeljudesuarez Airline Reservation System6/8/202417/6/2026
A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.3)0.65%—Angeljudesuarez Airline Reservation System6/8/202417/6/2026
A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack can be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.1)0.61%—Emiloimagtolis Ticket Reservation System3/8/202417/6/2026
A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The manipulation of the argument prefSeat_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
AnalizadaMedia (5.1)0.57%—Emiloimagtolis Ticket Reservation System3/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file checkout_ticket_save.php. The manipulation of the argument data leads to sql injection. The attack may be launched remotely. The exploit has…
AnalizadaMedia (6.9)0.65%—Emiloimagtolis Ticket Reservation System3/8/202417/6/2026
A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Login Page. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (6.9)0.65%—Fabian Online BUS Reservation Site31/7/202417/6/2026
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file register.php. The manipulation of the argument Email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.46%—Oretnom23 LOT Reservation Management System31/7/202417/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_settings. The manipulation of the argument about leads to cross site scripting. It is possible to initiate the attack remotely.…
Orbitaley — Vulnerabilidades