Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.40% | — | Digitaldruid Hoteldruid | 30/7/2024 | 17/6/2026 | Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values. | |
| Modificada | Media (6.9) | 0.68% | — | Clive 21 Simple Online Hotel Reservation System | 25/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Thimpress WP Hotel Booking | 20/6/2024 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Media (6.9) | 0.80% | — | Clive 21 Simple Online Hotel Reservation System | 18/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file edit_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The… | |
| Modificada | Media (6.9) | 0.80% | — | Clive 21 Simple Online Hotel Reservation System | 18/6/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file add_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has… | |
| Aplazada | Crítica (9.8) | 0.85% | — | Motopress Hotel Booking LiteAI | 14/5/2024 | 17/6/2026 | The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is… | |
| Analizada | Media (5.9) | 0.28% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 14/5/2024 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example)… | |
| Analizada | Alta (8.1) | 0.61% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 14/5/2024 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed… | |
| Aplazada | Crítica (9.8) | 1.9% | — | Infotel Conseil GlpiAI | 29/4/2024 | 17/6/2026 | An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input. | |
| Aplazada | Alta (7.1) | 0.39% | — | Vikbooking VIK Booking Hotel Booking Engine AND PMSAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VikBooking Hotel Booking Engine & PMS allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.6.7. | |
| Modificada | Crítica (9.8) | 0.52% | — | Thimpress WP Hotel Booking | 29/3/2024 | 17/6/2026 | Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2. | |
| Analizada | Crítica (9.8) | 0.78% | 💥 PoC | Pratham-jaiswal Hotel Booking Management System | 7/3/2024 | 17/6/2026 | Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php. | |
| Analizada | Alta (7.5) | 0.68% | 💥 PoC | Pratham-jaiswal Hotel Booking Management System | 7/3/2024 | 17/6/2026 | Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php. | |
| Modificada | Media (6.5) | 0.46% | — | Badge.team Hacker Hotel Badge 2024 | 11/2/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on risc-v (billboard modules) allows Flooding.This issue affects Hacker Hotel Badge 2024: from 0.1.0 through 0.1.3. | |
| Modificada | Alta (8.8) | 0.70% | — | Hotel Management System Project Hotel Management System | 9/2/2024 | 17/6/2026 | Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2. | |
| Modificada | Crítica (9.8) | 0.75% | — | Hotel Management System Project Hotel Management System | 9/2/2024 | 17/6/2026 | Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2. | |
| Modificada | Crítica (9.8) | 0.73% | — | Hotel Management System Project Hotel Management System | 9/2/2024 | 17/6/2026 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2. | |
| Modificada | Crítica (9.8) | 0.73% | — | Hotel Management System Project Hotel Management System | 9/2/2024 | 17/6/2026 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2. | |
| Modificada | Media (6.1) | 0.56% | — | Fabian Simple Online Hotel Reservation System | 13/1/2024 | 17/6/2026 | A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file add_reserve.php of the component Make a Reservation Page. The manipulation of the argument Firstname/Lastname with the input… | |
| Modificada | Crítica (9.8) | 0.71% | — | Code-projects Simple Online Hotel Reservation System | 10/1/2024 | 17/6/2026 | A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.21% | — | Yevhenkotelnytskyi JS & CSS Script Optimizer | 8/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Motopress Hotel Booking Lite | 26/12/2023 | 17/6/2026 | The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server | |
| Analizada | Media (5.4) | 0.37% | — | Jayesh Hotel Management System | 20/12/2023 | 17/6/2026 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. | |
| Analizada | Media (5.4) | 0.38% | — | Jayesh Hotel Management System | 20/12/2023 | 17/6/2026 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. | |
| Analizada | Media (5.4) | 0.38% | — | Jayesh Hotel Management System | 20/12/2023 | 17/6/2026 | Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. |