Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2700▼ 48 respecto a la semana anterior
Críticas / altas1449▲ 316 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

504 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.24%—Mage-people BUS Ticket Booking With Seat ReservationAI1/10/20261/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
AplazadaMedia (4.3)0.18%—Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI9/9/20269/9/2026
Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2.
AplazadaMedia (5.5)0.53%—Code-projects Hotel AND Tourism ReservationAI6/9/202611/9/2026
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may…
AplazadaBaja (2.1)0.47%—Code-projects Hotel AND Tourism ReservationAIPHPAI6/9/20268/9/2026
A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may…
AplazadaBaja (2.3)0.33%—Siteserver SscmsAI30/8/202631/8/2026
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to…
AplazadaMedia (6.9)0.34%—Cybertutor NewsiteserverAI24/8/202626/8/2026
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.
AplazadaMedia (5.1)0.23%—Cybertutor NewsiteserverAI24/8/202626/8/2026
NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.
AnalizadaAlta (8.8)0.43%—Oracle Teleservice18/8/202631/8/2026
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Request Form). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of…
AplazadaMedia (5.3)0.16%—Fivestarplugins Five Star Restaurant ReservationsAI6/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending…
AplazadaAlta (7.1)0.16%—Razer RzupdateserviceAI3/8/202612/8/2026
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to…
AplazadaAlta (7.5)0.39%—Fivestarplugins Five Star Restaurant ReservationsAI2/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the…
AplazadaAlta (7.2)8.8%—Planyo Online Reservation SystemAI11/7/202613/7/2026
The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The…
AplazadaMedia (6.4)0.35%—Starboard Suite Reservation CalendarsAI11/7/202629/9/2026
The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20267/7/2026
A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20267/7/2026
A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaBaja (2.1)0.37%—Sourcecodester Online Boat Reservation SystemAI5/7/20267/7/2026
A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AplazadaAlta (7.5)0.35%—Fivestarplugins Five Star Restaurant ReservationsAI25/6/202629/6/2026
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
AnalizadaAlta (8.8)0.49%—Cmsjunkie Multiplehotelreservation19/6/202619/8/2026
Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT…
AnalizadaAlta (8.8)0.49%—Cmsjunkie Jhotelreservation19/6/202619/8/2026
Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to…
AplazadaAlta (8.1)0.35%—PreservationAI17/6/202630/9/2026
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
AnalizadaMedia (6.1)0.34%—Commenthol Md-fileserver9/6/202612/8/2026
md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the…