Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.0%—Digitaldruid Hoteldruid26/8/202117/6/2026
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
ModificadaMedia (6.1)4.9%💥 ExploitDigitaldruid Hoteldruid3/8/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
ModificadaCrítica (9.8)4.1%💥 PoCDigitaldruid Hoteldruid3/8/202117/6/2026
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
ModificadaMedia (6.1)1.2%—Hotels Server Project Hotels Server10/5/202117/6/2026
Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php".
ModificadaCrítica (9.8)16%💥 ExploitThimpress WP Hotel Booking3/3/202117/6/2026
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
ModificadaMedia (5.4)0.60%—Online Hotel Booking System PRO Project Online Hotel Booking System PRO27/8/202017/6/2026
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
ModificadaMedia (6.1)1.2%—Online Hotel Booking System Project Online Hotel Booking System5/7/202017/6/2026
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
ModificadaMedia (6.5)1.2%—Hotels Styx12/3/202017/6/2026
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.
ModificadaCrítica (9.8)1.4%—Hotel AND Lodge Management System Project Hotel AND Lodge Management System23/10/201917/6/2026
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
ModificadaMedia (6.5)2.0%—Digitaldruid Hoteldruid24/6/201917/6/2026
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_contratto=1&n_file=a query string to…
ModificadaCrítica (9.8)2.2%—Scriptzee Hotel Booking Engine19/6/201917/6/2026
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
ModificadaCrítica (9.8)1.6%—Digitaldruid Hoteldruid7/6/201917/6/2026
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
ModificadaCrítica (9.8)1.6%—Digitaldruid Hoteldruid7/6/201917/6/2026
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
ModificadaMedia (4.9)1.7%—Digitaldruid Hoteldruid7/6/201917/6/2026
In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service…
ModificadaMedia (6.1)11%💥 ExploitDigitaldruid Hoteldruid17/5/201917/6/2026
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
ModificadaCrítica (9.8)1.1%—Hotels Server Project Hotels Server17/2/201917/6/2026
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
ModificadaAlta (7.5)0.94%—Hotels Server Project Hotels Server8/2/201917/6/2026
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
ModificadaCrítica (9.8)1.0%—Hotels Server Project Hotels Server20/1/201917/6/2026
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.
ModificadaCrítica (9.8)1.5%—Teknotel Cbw700n Firmware23/12/201817/6/2026
TEKNOTEL CBW700N 81.447.392110.729.024 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
ModificadaCrítica (9.8)1.6%—Digitaldruid Hoteldruid20/12/201817/6/2026
HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack appear to be exploitable via the attack can be done by anyone via…
ModificadaMedia (6.1)0.87%—Emetrotel Xain20/12/201817/6/2026
An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.
ModificadaMedia (6.5)1.1%—Hotel Booking Script Project Hotel Booking Script10/8/201817/6/2026
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
ModificadaMedia (5.4)0.55%—Hotel Booking Script Project Hotel Booking Script10/8/201817/6/2026
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
ModificadaCrítica (9.8)3.0%💥 ExploitHotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script13/12/201717/6/2026
Food Order Script 1.0 has SQL Injection via the /list city parameter.
ModificadaAlta (7.1)1.5%—Oracle Hospitality Hotel Mobile19/10/201717/6/2026
Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile.…
Orbitaley — Vulnerabilidades