Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
389 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | |
| Pendiente de análisis | Alta (8.8) | 1.5% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. | |
| Pendiente de análisis | Crítica (9.8) | 0.65% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. | |
| Pendiente de análisis | Media (5.4) | 0.44% | — | Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI | 18/9/2026 | 21/9/2026 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,… | |
| Pendiente de análisis | Media (5.7) | 0.22% | — | Suse ObservabilityAIRancher-extension-stackstateAI | 17/9/2026 | 29/9/2026 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment. | |
| Pendiente de análisis | Alta (7.7) | 0.47% | — | Redhat Multicluster Observability AddonAIRedhat Opentelemetry CollectorAIRedhat Cluster LOG ForwarderAI | 11/9/2026 | 21/9/2026 | A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on… | |
| Aplazada | Media (4.3) | 0.18% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI | 9/9/2026 | 9/9/2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hotel AND Tourism ReservationAI | 6/9/2026 | 11/9/2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Hotel AND Tourism ReservationAIPHPAI | 6/9/2026 | 8/9/2026 | A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may… | |
| Pendiente de análisis | Alta (7.7) | 0.31% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 10/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an… | |
| Pendiente de análisis | Crítica (9.6) | 0.21% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 8/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace… | |
| Pendiente de análisis | Media (6.2) | 0.52% | — | Opensearch Dashboards-observabilityAI | 21/8/2026 | 27/8/2026 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web… | |
| Aplazada | Media (5.3) | 0.16% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 6/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending… | |
| Aplazada | Alta (7.5) | 0.39% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the… | |
| Pendiente de análisis | Alta (7.3) | 0.33% | — | IBM Observability With Instana AgentAIInstana CoreAI | 28/7/2026 | 30/7/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API. | |
| Aplazada | Alta (7.2) | 8.8% | — | Planyo Online Reservation SystemAI | 11/7/2026 | 13/7/2026 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The… | |
| Aplazada | Media (6.4) | 0.35% | — | Starboard Suite Reservation CalendarsAI | 11/7/2026 | 29/9/2026 | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 7/7/2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 7/7/2026 | A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hotel AND Tourism ReservationAI | 5/7/2026 | 6/7/2026 | A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Boat Reservation SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. |