Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.4%💥 ExploitDigitaldruid Hoteldruid13/6/202317/6/2026
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
ModificadaAlta (8.8)1.5%💥 PoCDigitaldruid Hoteldruid13/6/202317/6/2026
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
ModificadaAlta (8.8)0.23%—Vikwp Vikbooking Hotel Booking Engine & PMS23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
ModificadaAlta (8.8)0.87%—Avirato Hotels Online Booking Engine8/5/202317/6/2026
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
ModificadaMedia (6.1)0.55%—Multi Language Hotel Management Software Project Multi Language Hotel Management Software7/5/202317/6/2026
A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problematic. This vulnerability affects unknown code of the file ajax.php of the component POST Parameter Handler. The manipulation of the argument complaint_type with the input…
ModificadaMedia (5.4)0.66%💥 PoCDigitaldruid Hoteldruid3/5/202317/6/2026
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
ModificadaMedia (4.8)0.39%—Vikwp Vikbooking Hotel Booking Engine & PMS6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions.
ModificadaAlta (8.8)0.91%—E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+727/3/202317/6/2026
The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before…
ModificadaCrítica (9.8)0.77%—Fabian Simple Online Hotel Reservation System22/3/202317/6/2026
A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file add_room.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-223554 is the identifier assigned to this…
ModificadaCrítica (9.8)0.87%💥 PoCFabian Responsive Hotel Site19/3/202317/6/2026
A vulnerability classified as critical has been found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file messages.php of the component Newsletter Log Handler. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit…
ModificadaCrítica (9.8)0.82%—Hotels Server Project Hotels Server17/2/202317/6/2026
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
ModificadaMedia (5.4)0.45%—Hotel Management System Project Hotel Management System13/1/202317/6/2026
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
ModificadaMedia (6.5)0.71%—Hotel Management System Project Hotel Management System13/1/202317/6/2026
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
ModificadaMedia (6.5)0.84%💥 PoCGoteleport Teleport8/12/20229/7/2026
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
ModificadaMedia (6.1)0.49%—Infotel Tasklists10/11/202217/6/2026
tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross-site Scripting (XSS) - Create XSS in task content (when add it). This issue is patched in version 2.0.3. There are no known workarounds.
ModificadaMedia (5.4)0.65%💥 PoCHotelmanager Project Hotelmanager4/11/202217/6/2026
Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.
ModificadaMedia (6.5)0.38%—Laubrotel Lbstopattack25/10/202217/6/2026
The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections.
ModificadaBaja (3.7)0.85%💥 PoCDigitaldruid Hoteldruid16/9/202217/6/2026
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
ModificadaCrítica (9.8)7.3%💥 PoCDigitaldruid Hoteldruid16/9/202217/6/2026
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
ModificadaMedia (5.4)0.76%—Hotel Management System Project Hotel Management System12/9/202217/6/2026
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
ModificadaCrítica (9.8)1.5%—Exotel Project Exotel27/8/202217/6/2026
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
ModificadaAlta (8.8)50%💥 ExploitGoteleport Teleport24/8/202217/6/2026
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack.…
ModificadaAlta (8)0.39%—Thimpress WP Hotel Booking22/8/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
ModificadaAlta (8.8)0.55%—Rigatur Online Booking AND Hotel Management System5/8/202217/6/2026
A vulnerability was found in Rigatur Online Booking and Hotel Management System aff6409. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Request Handler. The manipulation of the argument email/pass leads to sql injection. The…
ModificadaCrítica (9.8)0.78%—Multi Language Hotel Management Software Project Multi Language Hotel Management Software4/8/202217/6/2026
A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
Orbitaley — Vulnerabilidades