Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.0%—Hotels Server Project Hotels Server20/1/201917/6/2026
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.
ModificadaCrítica (9.8)1.6%—Digitaldruid Hoteldruid20/12/201817/6/2026
HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack appear to be exploitable via the attack can be done by anyone via…
ModificadaMedia (6.5)1.1%—Hotel Booking Script Project Hotel Booking Script10/8/201817/6/2026
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
ModificadaMedia (5.4)0.55%—Hotel Booking Script Project Hotel Booking Script10/8/201817/6/2026
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
ModificadaCrítica (9.8)3.0%💥 ExploitHotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script13/12/201717/6/2026
Food Order Script 1.0 has SQL Injection via the /list city parameter.
ModificadaAlta (7.1)1.5%—Oracle Hospitality Hotel Mobile19/10/201717/6/2026
Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile.…
ModificadaBaja (3.5)0.78%—Oracle Hospitality Hotel Mobile19/10/201717/6/2026
Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile.…
ModificadaMedia (5.5)0.43%—Oracle Hospitality Hotel Mobile8/8/201717/6/2026
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Android). The supported version that is affected is 1.01. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Hospitality Hotel Mobile executes to…
ModificadaMedia (4.6)0.38%—Oracle Hospitality Hotel Mobile8/8/201717/6/2026
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Windows). The supported version that is affected is 1.1. Difficult to exploit vulnerability allows physical access to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can…
ModificadaMedia (4.3)1.3%—Oracle Hospitality Hotel Mobile8/8/201717/6/2026
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RestAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful…
ModificadaMedia (4.3)1.3%—Oracle Hospitality Hotel Mobile8/8/201717/6/2026
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/iOS). The supported version that is affected is 1.05. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful attacks…
ModificadaCrítica (9.1)2.3%—Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking6/10/201617/6/2026
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
ModificadaMedia (6.5)1.1%—Loenshotel Phprechnung11/10/201517/6/2026
SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.5)1.1%—Apphp Hotel Site22/6/201517/6/2026
SQL injection vulnerability in ApPHP Hotel Site 3.x.x allows remote editors to execute arbitrary SQL commands via the pid parameter to index.php.
ModificadaMedia (5)2.2%—Joomlaskin JS Multi Hotel13/1/201517/6/2026
The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7)…
ModificadaMedia (4.3)2.0%—Joomlaskin JS Multi Hotel13/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
ModificadaMedia (4.3)2.0%—Joomlaskin JS Multi Hotel9/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter.
ModificadaMedia (5.4)0.27%—Macedonia Hacienda Hotel Project Macedonia Hacienda Hotel21/10/201417/6/2026
The Macedonia Hacienda Hotel (aka appinventor.ai_orolimpio999.HotelMacedonia) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Tiket.com Hotel & Flight21/10/201417/6/2026
The Tiket.com Hotel & Flight (aka com.tiket.gits) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Mygoodhotels Booking Discount21/10/201417/6/2026
The BOOKING DISCOUNT (aka com.wmygoodhotelscom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Hotel-room Hotel Room21/10/201417/6/2026
The Hotel Room (aka com.wHotelRoom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Conrad Hotel Project Conrad Hotel21/10/201417/6/2026
The Conrad Hotel (aka com.wConradHotel) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Djogjahotel Liburan Hemat19/10/201417/6/2026
The Liburan Hemat (aka com.liburan.bro) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Happylabs Hotel Story\9/9/201417/6/2026
The Hotel Story: Resort Simulation (aka com.happylabs.hotelstory) application 1.7.9B for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)3.3%💥 ExploitBestsoftinc Advance Hotel Booking System11/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
Orbitaley — Vulnerabilidades