Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.70% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 14/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.61% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 29/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects an unknown part of the file user\operations\payment_operation.php. The manipulation of the argument booking_id leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Alta (8.8) | 0.72% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 28/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file /user/s.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.2) | 0.70% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 28/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management System 1.0. This issue affects some unknown processing of the file admin/practice_pdf.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit… | |
| Modificada | Media (4.7) | 0.58% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects an unknown part of the file admin/expense_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Modificada | Media (4.7) | 0.62% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this issue is some unknown functionality of the file admin/expense_report.php. The manipulation of the argument from_date leads to sql injection. The attack may be launched… | |
| Modificada | Media (4.7) | 0.58% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/disapprove_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit… | |
| Modificada | Media (4.7) | 0.58% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/booking_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.60% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/approve_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (6.3) | 0.56% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/add_payment.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.3) | 0.56% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin/abc.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 1.0% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 26/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been… | |
| Modificada | Alta (7.2) | 1.0% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 26/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been… | |
| Modificada | Crítica (9.8) | 19% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 16/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Alta (7.5) | 1.0% | — | Opensuse Travel Support Program | 10/1/2023 | 17/6/2026 | Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of travel-support-program below the patched version is affected. The travel-support-program uses the… | |
| Modificada | Crítica (9.8) | 0.89% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 28/11/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. | |
| Modificada | Alta (7.2) | 1.0% | — | Online Tours AND Travels Management System Project Online Tours AND Travels Management System | 7/11/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.2) | 1.0% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 3/11/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.2) | 1.2% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 18/10/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.2) | 1.1% | — | Online Tours AND Travels Management System Project Online Tours AND Travels Management System | 17/10/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php. | |
| Modificada | Alta (7.2) | 0.78% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 14/10/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php. | |
| Modificada | Media (6.1) | 0.61% | — | Cowell Enterprise Travel Management System Project Cowell Enterprise Travel Management System | 28/9/2022 | 17/6/2026 | Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack. | |
| Modificada | Alta (7.2) | 0.97% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/9/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php. | |
| Modificada | Alta (7.2) | 0.97% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/9/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php. | |
| Modificada | Alta (7.2) | 0.86% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 27/9/2022 | 17/6/2026 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php. |