Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)2.8%💥 ExploitDigitaldruid Hoteldruid26/4/202217/6/2026
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
ModificadaMedia (5.3)1.1%—Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin19/4/202217/6/2026
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
ModificadaCrítica (9.8)1.7%—Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin19/4/202217/6/2026
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
ModificadaMedia (6.1)0.79%—Hotel Management System Project Hotel Management System13/4/202217/6/2026
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.
ModificadaAlta (8.8)45%💥 ExploitDigitaldruid Hoteldruid3/3/202217/6/2026
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
ModificadaAlta (8.8)3.1%—Kea-hotel-erp Project Kea-hotel-erp25/1/202217/6/2026
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
ModificadaAlta (7.5)2.4%💥 PoCHotel Management System Project Hotel Management System4/10/202117/6/2026
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.
ModificadaCrítica (9.8)3.5%—Hotel AND Lodge Booking Management System Project Hotel AND Lodge Booking Management System1/10/202117/6/2026
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
ModificadaMedia (6.1)1.0%—Digitaldruid Hoteldruid26/8/202117/6/2026
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
ModificadaMedia (6.1)4.9%💥 ExploitDigitaldruid Hoteldruid3/8/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
ModificadaCrítica (9.8)4.1%💥 PoCDigitaldruid Hoteldruid3/8/202117/6/2026
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
ModificadaMedia (6.1)1.2%—Hotels Server Project Hotels Server10/5/202117/6/2026
Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php".
ModificadaCrítica (9.8)16%💥 ExploitThimpress WP Hotel Booking3/3/202117/6/2026
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
ModificadaMedia (5.4)0.60%—Online Hotel Booking System PRO Project Online Hotel Booking System PRO27/8/202017/6/2026
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
ModificadaMedia (6.1)1.2%—Online Hotel Booking System Project Online Hotel Booking System5/7/202017/6/2026
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
ModificadaMedia (6.5)1.2%—Hotels Styx12/3/202017/6/2026
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.
ModificadaCrítica (9.8)1.4%—Hotel AND Lodge Management System Project Hotel AND Lodge Management System23/10/201917/6/2026
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
ModificadaMedia (6.5)2.0%—Digitaldruid Hoteldruid24/6/201917/6/2026
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_contratto=1&n_file=a query string to…
ModificadaCrítica (9.8)2.2%—Scriptzee Hotel Booking Engine19/6/201917/6/2026
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
ModificadaCrítica (9.8)1.6%—Digitaldruid Hoteldruid7/6/201917/6/2026
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
ModificadaCrítica (9.8)1.6%—Digitaldruid Hoteldruid7/6/201917/6/2026
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
ModificadaMedia (4.9)1.7%—Digitaldruid Hoteldruid7/6/201917/6/2026
In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service…
ModificadaMedia (6.1)11%💥 ExploitDigitaldruid Hoteldruid17/5/201917/6/2026
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
ModificadaCrítica (9.8)1.1%—Hotels Server Project Hotels Server17/2/201917/6/2026
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
ModificadaAlta (7.5)0.94%—Hotels Server Project Hotels Server8/2/201917/6/2026
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
Orbitaley — Vulnerabilidades