Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Hotels Server Project Hotels Server | 20/1/2019 | 17/6/2026 | Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Digitaldruid Hoteldruid | 20/12/2018 | 17/6/2026 | HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack appear to be exploitable via the attack can be done by anyone via… | |
| Modificada | Media (6.5) | 1.1% | — | Hotel Booking Script Project Hotel Booking Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field. | |
| Modificada | Media (5.4) | 0.55% | — | Hotel Booking Script Project Hotel Booking Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Hotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script | 13/12/2017 | 17/6/2026 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Alta (7.1) | 1.5% | — | Oracle Hospitality Hotel Mobile | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile.… | |
| Modificada | Baja (3.5) | 0.78% | — | Oracle Hospitality Hotel Mobile | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile.… | |
| Modificada | Media (5.5) | 0.43% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Android). The supported version that is affected is 1.01. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Hospitality Hotel Mobile executes to… | |
| Modificada | Media (4.6) | 0.38% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Windows). The supported version that is affected is 1.1. Difficult to exploit vulnerability allows physical access to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RestAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/iOS). The supported version that is affected is 1.05. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful attacks… | |
| Modificada | Crítica (9.1) | 2.3% | — | Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking | 6/10/2016 | 17/6/2026 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 | |
| Modificada | Media (6.5) | 1.1% | — | Loenshotel Phprechnung | 11/10/2015 | 17/6/2026 | SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Apphp Hotel Site | 22/6/2015 | 17/6/2026 | SQL injection vulnerability in ApPHP Hotel Site 3.x.x allows remote editors to execute arbitrary SQL commands via the pid parameter to index.php. | |
| Modificada | Media (5) | 2.2% | — | Joomlaskin JS Multi Hotel | 13/1/2015 | 17/6/2026 | The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7)… | |
| Modificada | Media (4.3) | 2.0% | — | Joomlaskin JS Multi Hotel | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Joomlaskin JS Multi Hotel | 9/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Macedonia Hacienda Hotel Project Macedonia Hacienda Hotel | 21/10/2014 | 17/6/2026 | The Macedonia Hacienda Hotel (aka appinventor.ai_orolimpio999.HotelMacedonia) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Tiket.com Hotel & Flight | 21/10/2014 | 17/6/2026 | The Tiket.com Hotel & Flight (aka com.tiket.gits) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mygoodhotels Booking Discount | 21/10/2014 | 17/6/2026 | The BOOKING DISCOUNT (aka com.wmygoodhotelscom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Hotel-room Hotel Room | 21/10/2014 | 17/6/2026 | The Hotel Room (aka com.wHotelRoom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Conrad Hotel Project Conrad Hotel | 21/10/2014 | 17/6/2026 | The Conrad Hotel (aka com.wConradHotel) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Djogjahotel Liburan Hemat | 19/10/2014 | 17/6/2026 | The Liburan Hemat (aka com.liburan.bro) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Happylabs Hotel Story\ | 9/9/2014 | 17/6/2026 | The Hotel Story: Resort Simulation (aka com.happylabs.hotelstory) application 1.7.9B for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. |