Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Travel Management System Project Travel Management System | 23/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Travel Management System Project Travel Management System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php. | |
| Modificada | Media (6.1) | 1.5% | — | Projectworlds Travel Management System | 17/5/2021 | 17/6/2026 | XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field | |
| Modificada | Media (4.3) | 0.58% | — | Fiori Apps 2.0 FOR Travel Management IN SAP ERP | 13/4/2021 | 17/6/2026 | SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation of privileges. However, the attacker can only read some information like last name, first name of… | |
| Modificada | Crítica (9.8) | 3.7% | — | Projectworlds Travel Management System | 27/8/2020 | 17/6/2026 | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution. | |
| Modificada | Alta (8.1) | 0.71% | — | SAP HCM Travel Management | 12/8/2020 | 17/6/2026 | SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check. | |
| Modificada | Media (5.4) | 0.52% | — | Hcltech Traveler | 18/10/2019 | 17/6/2026 | HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the… | |
| Modificada | Media (4.7) | 0.70% | — | Traveloka | 21/9/2019 | 17/6/2026 | The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has… | |
| Modificada | Media (6.1) | 1.3% | — | Travel Management Project Travel Management | 29/8/2019 | 17/6/2026 | The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | |
| Modificada | Media (6.1) | 0.88% | — | API Based Travel Booking Project API Based Travel Booking | 6/6/2019 | 17/6/2026 | An issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-results.php d2 parameter. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+8 | 9/5/2019 | 17/6/2026 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i… | |
| Modificada | Alta (7.5) | 1.0% | — | Travelcoins Travelcointoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for TravelCoin (TRV), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Travelcoin | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for TravelCoin (TRV), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 1.1% | — | Travelzeditoken Project Travelzeditoken | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for TravelZedi Token (ZEDI), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.1) | 2.1% | — | IBM Traveler | 17/7/2016 | 17/6/2026 | IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (6.8) | 3.8% | 💥 Exploit | AB Google MAP Travel Project AB Google MAP Travel | 1/4/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3)… | |
| Modificada | Media (4.3) | 1.8% | — | IBM Notes Traveler Companion | 2/3/2015 | 17/6/2026 | The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a… | |
| Modificada | Media (5) | 1.9% | — | IBM Notes Traveler | 4/11/2014 | 17/6/2026 | The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Travel+leisure | 21/10/2014 | 17/6/2026 | The Travel+Leisure (aka com.magzter.travelleisure) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Touriosity Travelmag | 21/10/2014 | 17/6/2026 | The Touriosity Travelmag (aka com.magzter.touriositytravelmag) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Netjapan Tsushima Travel Guide | 23/9/2014 | 17/6/2026 | The Tsushima Travel Guide (aka com.netjapan.ntsushima) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Travelzadcomvb | 18/9/2014 | 17/6/2026 | The travelzadcomvb (aka com.tapatalk.travelzadcomvb) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Pointinside Point Inside Shopping & Travel | 9/9/2014 | 17/6/2026 | The Point Inside Shopping & Travel (aka com.pointinside.android.app) application 3.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 1.2% | — | Satechi Smart Travel Router | 30/11/2013 | 17/6/2026 | The web interface on the Satechi travel router 1.5, when Wi-Fi is used for WAN access, exposes the console without authentication on the WAN IP address regardless of the "Web Management via WAN" setting, which allows remote attackers to bypass intended access restrictions via HTTP requests. | |
| Modificada | Alta (7.2) | 0.37% | — | IBM Lotus InotesIBM Lotus NotesIBM Lotus Notes Traveler | 21/6/2013 | 16/6/2026 | ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24. |