Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.5)0.28%—Apple MailAIApple CalendarAIApple ContactsAIHCL TravelerAI26/8/202628/8/2026
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the…
AplazadaMedia (6.5)0.16%—HCL Traveler FOR Microsoft OutlookAI17/7/202617/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaAlta (7.8)0.27%—Hcltech Traveler FOR Microsoft Outlook27/6/20266/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party…
AnalizadaMedia (5.5)0.15%—Hcltech Traveler FOR Microsoft Outlook27/6/202629/9/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
AnalizadaAlta (7.8)0.09%—Hcltech Traveler FOR Microsoft Outlook26/6/20261/10/2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
Pendiente de análisisMedia (6.3)0.15%—HCL TravelerAI24/3/202617/6/2026
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
AnalizadaMedia (4.3)0.28%—Hcltech Traveler24/3/202617/6/2026
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain…
AplazadaCrítica (9.8)0.56%—Shinetheme TravelerAI18/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.
AplazadaAlta (8.5)0.24%—Shinetheme TravelerAI22/1/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.8.
AplazadaMedia (6.5)0.29%—Shinetheme TravelerAI8/1/20267/10/2026
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.
ModificadaMedia (5.4)0.22%—Qodeinteractive Backpack Traveler30/12/20257/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3.
AplazadaAlta (8.1)0.40%—Shinetheme TravelerAI18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PHP Local File Inclusion.This issue affects Traveler: from n/a through < 3.2.6.
AplazadaAlta (7.1)0.18%—Shinetheme TravelerAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.6.
AplazadaAlta (8.5)0.25%—Shinetheme TravelerAI18/12/20255/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.6.
AplazadaBaja (2.7)0.27%—Shinetheme Traveler Option TreeAI16/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree allows Retrieve Embedded Sensitive Data.This issue affects Traveler Option Tree: from n/a through <= 2.8.
AplazadaMedia (5.3)0.25%—Shinetheme TravelerAI9/12/202517/6/2026
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.
AplazadaMedia (6.5)0.15%—Camille V Travelers MAPAI21/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Travelers' Map travelers-map allows Stored XSS.This issue affects Travelers' Map: from n/a through <= 2.3.2.
AnalizadaMedia (5.5)0.16%—Hcltech Traveler FOR Microsoft Outlook16/10/20251/10/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
AplazadaAlta (7.1)0.24%—Shinetheme TravelerAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.3.
AplazadaAlta (7.5)0.38%—Shinetheme TravelerAI26/9/202517/6/2026
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through < 3.2.3.
AplazadaCrítica (9.3)0.40%—Shinetheme TravelerAI16/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows SQL Injection.This issue affects Traveler: from n/a through < 3.2.2.
AnalizadaCrítica (9.8)0.27%—Hcltech Traveler FOR Microsoft Outlook30/5/202517/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaCrítica (9.8)0.27%—Hcltech Traveler FOR Microsoft Outlook30/5/202517/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
ModificadaAlta (8.1)0.78%—Qodeinteractive Backpack Traveler23/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows PHP Local File Inclusion.This issue affects Backpack Traveler: from n/a through <= 2.10.2.
AnalizadaMedia (4.3)0.30%—Hcltech Traveler3/4/202517/6/2026
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch…
Orbitaley — Vulnerabilidades