Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.4% | 💥 Exploit | Digitaldruid Hoteldruid | 13/6/2023 | 17/6/2026 | A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data. | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Digitaldruid Hoteldruid | 13/6/2023 | 17/6/2026 | hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Alta (8.8) | 0.23% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions. | |
| Modificada | Alta (8.8) | 0.87% | — | Avirato Hotels Online Booking Engine | 8/5/2023 | 17/6/2026 | The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks. | |
| Modificada | Media (6.1) | 0.55% | — | Multi Language Hotel Management Software Project Multi Language Hotel Management Software | 7/5/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problematic. This vulnerability affects unknown code of the file ajax.php of the component POST Parameter Handler. The manipulation of the argument complaint_type with the input… | |
| Modificada | Media (5.4) | 0.66% | 💥 PoC | Digitaldruid Hoteldruid | 3/5/2023 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function. | |
| Modificada | Media (4.8) | 0.39% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions. | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Crítica (9.8) | 0.77% | — | Fabian Simple Online Hotel Reservation System | 22/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file add_room.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-223554 is the identifier assigned to this… | |
| Modificada | Crítica (9.8) | 0.87% | 💥 PoC | Fabian Responsive Hotel Site | 19/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file messages.php of the component Newsletter Log Handler. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.82% | — | Hotels Server Project Hotels Server | 17/2/2023 | 17/6/2026 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. | |
| Modificada | Media (5.4) | 0.45% | — | Hotel Management System Project Hotel Management System | 13/1/2023 | 17/6/2026 | Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php. | |
| Modificada | Media (6.5) | 0.71% | — | Hotel Management System Project Hotel Management System | 13/1/2023 | 17/6/2026 | Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php. | |
| Modificada | Media (6.5) | 0.84% | 💥 PoC | Goteleport Teleport | 8/12/2022 | 9/7/2026 | Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface. | |
| Modificada | Media (6.1) | 0.49% | — | Infotel Tasklists | 10/11/2022 | 17/6/2026 | tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross-site Scripting (XSS) - Create XSS in task content (when add it). This issue is patched in version 2.0.3. There are no known workarounds. | |
| Modificada | Media (5.4) | 0.65% | 💥 PoC | Hotelmanager Project Hotelmanager | 4/11/2022 | 17/6/2026 | Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields. | |
| Modificada | Media (6.5) | 0.38% | — | Laubrotel Lbstopattack | 25/10/2022 | 17/6/2026 | The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible for attackers to conduct CSRF attacks. This could allow attackers to disable the plugin's protections. | |
| Modificada | Baja (3.7) | 0.85% | 💥 PoC | Digitaldruid Hoteldruid | 16/9/2022 | 17/6/2026 | HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's. | |
| Modificada | Crítica (9.8) | 7.3% | 💥 PoC | Digitaldruid Hoteldruid | 16/9/2022 | 17/6/2026 | The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks. | |
| Modificada | Media (5.4) | 0.76% | — | Hotel Management System Project Hotel Management System | 12/9/2022 | 17/6/2026 | Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname". | |
| Modificada | Crítica (9.8) | 1.5% | — | Exotel Project Exotel | 27/8/2022 | 17/6/2026 | The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party. | |
| Modificada | Alta (8.8) | 50% | 💥 Exploit | Goteleport Teleport | 24/8/2022 | 17/6/2026 | Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack.… | |
| Modificada | Alta (8) | 0.39% | — | Thimpress WP Hotel Booking | 22/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress. | |
| Modificada | Alta (8.8) | 0.55% | — | Rigatur Online Booking AND Hotel Management System | 5/8/2022 | 17/6/2026 | A vulnerability was found in Rigatur Online Booking and Hotel Management System aff6409. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Request Handler. The manipulation of the argument email/pass leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 0.78% | — | Multi Language Hotel Management Software Project Multi Language Hotel Management Software | 4/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… |