Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.8% | 💥 Exploit | Digitaldruid Hoteldruid | 26/4/2022 | 17/6/2026 | HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php. | |
| Modificada | Media (5.3) | 1.1% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests. | |
| Modificada | Crítica (9.8) | 1.7% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | |
| Modificada | Media (6.1) | 0.79% | — | Hotel Management System Project Hotel Management System | 13/4/2022 | 17/6/2026 | Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded. | |
| Modificada | Alta (8.8) | 45% | 💥 Exploit | Digitaldruid Hoteldruid | 3/3/2022 | 17/6/2026 | HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module. | |
| Modificada | Alta (8.8) | 3.1% | — | Kea-hotel-erp Project Kea-hotel-erp | 25/1/2022 | 17/6/2026 | In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service. | |
| Modificada | Alta (7.5) | 2.4% | 💥 PoC | Hotel Management System Project Hotel Management System | 4/10/2021 | 17/6/2026 | A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php. | |
| Modificada | Crítica (9.8) | 3.5% | — | Hotel AND Lodge Booking Management System Project Hotel AND Lodge Booking Management System | 1/10/2021 | 17/6/2026 | Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details. | |
| Modificada | Media (6.1) | 1.0% | — | Digitaldruid Hoteldruid | 26/8/2021 | 17/6/2026 | DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter. | |
| Modificada | Media (6.1) | 4.9% | 💥 Exploit | Digitaldruid Hoteldruid | 3/8/2021 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands. | |
| Modificada | Crítica (9.8) | 4.1% | 💥 PoC | Digitaldruid Hoteldruid | 3/8/2021 | 17/6/2026 | A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Hotels Server Project Hotels Server | 10/5/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php". | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Thimpress WP Hotel Booking | 3/3/2021 | 17/6/2026 | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. | |
| Modificada | Media (5.4) | 0.60% | — | Online Hotel Booking System PRO Project Online Hotel Booking System PRO | 27/8/2020 | 17/6/2026 | Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags. | |
| Modificada | Media (6.1) | 1.2% | — | Online Hotel Booking System Project Online Hotel Booking System | 5/7/2020 | 17/6/2026 | An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields. | |
| Modificada | Media (6.5) | 1.2% | — | Hotels Styx | 12/3/2020 | 17/6/2026 | Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header. | |
| Modificada | Crítica (9.8) | 1.4% | — | Hotel AND Lodge Management System Project Hotel AND Lodge Management System | 23/10/2019 | 17/6/2026 | Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details. | |
| Modificada | Media (6.5) | 2.0% | — | Digitaldruid Hoteldruid | 24/6/2019 | 17/6/2026 | Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_contratto=1&n_file=a query string to… | |
| Modificada | Crítica (9.8) | 2.2% | — | Scriptzee Hotel Booking Engine | 19/6/2019 | 17/6/2026 | SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Digitaldruid Hoteldruid | 7/6/2019 | 17/6/2026 | HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Digitaldruid Hoteldruid | 7/6/2019 | 17/6/2026 | HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter. | |
| Modificada | Media (4.9) | 1.7% | — | Digitaldruid Hoteldruid | 7/6/2019 | 17/6/2026 | In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service… | |
| Modificada | Media (6.1) | 11% | 💥 Exploit | Digitaldruid Hoteldruid | 17/5/2019 | 17/6/2026 | HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Hotels Server Project Hotels Server | 17/2/2019 | 17/6/2026 | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled. | |
| Modificada | Alta (7.5) | 0.94% | — | Hotels Server Project Hotels Server | 8/2/2019 | 17/6/2026 | controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage. |