Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 48 respecto a la semana anterior
Críticas / altas1449▲ 316 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
504 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | |
| Aplazada | Media (4.3) | 0.18% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI | 9/9/2026 | 9/9/2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hotel AND Tourism ReservationAI | 6/9/2026 | 11/9/2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Hotel AND Tourism ReservationAIPHPAI | 6/9/2026 | 8/9/2026 | A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Baja (2.3) | 0.33% | — | Siteserver SscmsAI | 30/8/2026 | 31/8/2026 | A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to… | |
| Aplazada | Media (6.9) | 0.34% | — | Cybertutor NewsiteserverAI | 24/8/2026 | 26/8/2026 | NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school. | |
| Aplazada | Media (5.1) | 0.23% | — | Cybertutor NewsiteserverAI | 24/8/2026 | 26/8/2026 | NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting. | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Teleservice | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Request Form). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of… | |
| Aplazada | Media (5.3) | 0.16% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 6/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending… | |
| Aplazada | Alta (7.1) | 0.16% | — | Razer RzupdateserviceAI | 3/8/2026 | 12/8/2026 | A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to… | |
| Aplazada | Alta (7.5) | 0.39% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the… | |
| Aplazada | Alta (7.2) | 8.8% | — | Planyo Online Reservation SystemAI | 11/7/2026 | 13/7/2026 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The… | |
| Aplazada | Media (6.4) | 0.35% | — | Starboard Suite Reservation CalendarsAI | 11/7/2026 | 29/9/2026 | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 7/7/2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 7/7/2026 | A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Boat Reservation SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie Multiplehotelreservation | 19/6/2026 | 19/8/2026 | Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT… | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie Jhotelreservation | 19/6/2026 | 19/8/2026 | Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to… | |
| Aplazada | Alta (8.1) | 0.35% | — | PreservationAI | 17/6/2026 | 30/9/2026 | Unauthenticated Local File Inclusion in Preservation <= 1.10 versions. | |
| Analizada | Media (6.1) | 0.34% | — | Commenthol Md-fileserver | 9/6/2026 | 12/8/2026 | md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the… |