Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.78% | — | Oracle Hospitality Hotel Mobile | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile.… | |
| Modificada | Media (5.5) | 0.43% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Android). The supported version that is affected is 1.01. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Hospitality Hotel Mobile executes to… | |
| Modificada | Media (4.6) | 0.38% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Windows). The supported version that is affected is 1.1. Difficult to exploit vulnerability allows physical access to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RestAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Hospitality Hotel Mobile | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/iOS). The supported version that is affected is 1.05. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful attacks… | |
| Modificada | Crítica (9.1) | 2.3% | — | Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking | 6/10/2016 | 17/6/2026 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 | |
| Modificada | Media (6.5) | 1.1% | — | Loenshotel Phprechnung | 11/10/2015 | 17/6/2026 | SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Apphp Hotel Site | 22/6/2015 | 17/6/2026 | SQL injection vulnerability in ApPHP Hotel Site 3.x.x allows remote editors to execute arbitrary SQL commands via the pid parameter to index.php. | |
| Modificada | Media (5) | 2.2% | — | Joomlaskin JS Multi Hotel | 13/1/2015 | 17/6/2026 | The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7)… | |
| Modificada | Media (4.3) | 2.0% | — | Joomlaskin JS Multi Hotel | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Joomlaskin JS Multi Hotel | 9/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Macedonia Hacienda Hotel Project Macedonia Hacienda Hotel | 21/10/2014 | 17/6/2026 | The Macedonia Hacienda Hotel (aka appinventor.ai_orolimpio999.HotelMacedonia) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Tiket.com Hotel & Flight | 21/10/2014 | 17/6/2026 | The Tiket.com Hotel & Flight (aka com.tiket.gits) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mygoodhotels Booking Discount | 21/10/2014 | 17/6/2026 | The BOOKING DISCOUNT (aka com.wmygoodhotelscom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Hotel-room Hotel Room | 21/10/2014 | 17/6/2026 | The Hotel Room (aka com.wHotelRoom) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Conrad Hotel Project Conrad Hotel | 21/10/2014 | 17/6/2026 | The Conrad Hotel (aka com.wConradHotel) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Djogjahotel Liburan Hemat | 19/10/2014 | 17/6/2026 | The Liburan Hemat (aka com.liburan.bro) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Happylabs Hotel Story\ | 9/9/2014 | 17/6/2026 | The Hotel Story: Resort Simulation (aka com.happylabs.hotelstory) application 1.7.9B for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Videotelecom Russkoe TB HD | 9/9/2014 | 17/6/2026 | The russkoe TB HD (aka com.videotelecom.russkoeHD) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Useasdf 4444 Hotel Booking Portal | 11/4/2012 | 16/6/2026 | SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 8/7/2011 | 16/6/2026 | SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Laubrotel G.cms Generator | 24/6/2010 | 16/6/2026 | SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Carlos Eduardo Sotelo Pinto 0.1.0 | 6/5/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Tourismscripts Tourism Script Accomodation Hotel Booking Portal Script | 18/1/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php. |