Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.21% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.33% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 23/7/2026 | A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Username leads to sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Ship Ferry Ticket Reservation SystemAI | 5/6/2026 | 23/7/2026 | A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack may be launched… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Concert Ticket Reservation SystemAI | 5/4/2026 | 24/7/2026 | A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql… | |
| Analizada | Media (4.8) | 0.32% | — | Fabian Train Ticket Reservation System | 28/4/2025 | 17/6/2026 | A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is the function Reservation of the component Ticket Reservation. The manipulation of the argument Name leads to stack-based buffer overflow. Attacking locally is a… | |
| Analizada | Media (5.3) | 0.50% | — | Fabian Online Ticket Reservation System | 7/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /passenger.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.36% | — | Fabian Train Ticket Reservation System | 17/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0. This affects an unknown part of the component Login Form. The manipulation of the argument username leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed… | |
| Modificada | Media (5.4) | 0.30% | — | Kjayvik BUS Ticket Reservation System | 23/8/2024 | 17/6/2026 | Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php. | |
| Analizada | Crítica (9.8) | 0.69% | — | Kjayvik BUS Ticket Reservation System | 23/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters. | |
| Analizada | Crítica (9.4) | 0.30% | — | Kjayvik BUS Ticket Reservation System | 23/8/2024 | 17/6/2026 | Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php. | |
| Analizada | Media (5.4) | 0.44% | — | Kjayvik BUS Ticket Reservation System | 22/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the "bookingdate" parameter. | |
| Analizada | Media (5.4) | 0.44% | — | Kjayvik BUS Ticket Reservation System | 22/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the Name, Phone, and Email parameter fields. | |
| Analizada | Media (6.1) | 0.47% | — | Kjayvik BUS Ticket Reservation System | 22/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via scheduleDurationPHP parameter. | |
| Analizada | Media (5.1) | 0.61% | — | Emiloimagtolis Ticket Reservation System | 3/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The manipulation of the argument prefSeat_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.1) | 0.57% | — | Emiloimagtolis Ticket Reservation System | 3/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file checkout_ticket_save.php. The manipulation of the argument data leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.65% | — | Emiloimagtolis Ticket Reservation System | 3/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Login Page. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Crítica (9.8) | 0.86% | — | Sanchitkmr Airline Ticket Reservation System | 5/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipulation of the argument jet_id leads to sql injection. The attack may be initiated remotely. The… |