Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. | |
| Modificada | Media (5.4) | 0.45% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. | |
| Modificada | Media (6.1) | 1.8% | — | Phpjabbers Availability Booking Calendar | 3/8/2023 | 17/6/2026 | A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible… | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The… | |
| Modificada | Media (6.1) | 0.39% | — | Gzscripts Availability Booking Calendar PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site… |