Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.55%—Hotel Management SystemAI20/8/202417/6/2026
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.
AnalizadaCrítica (9.8)0.72%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
AnalizadaAlta (8.8)0.34%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaCrítica (9.8)0.74%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
AnalizadaAlta (8.8)0.30%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.58%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.
AnalizadaAlta (8.8)0.31%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaAlta (8.6)0.53%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.
ModificadaAlta (8.8)0.70%—Hotel Management System Project Hotel Management System9/2/202417/6/2026
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.
ModificadaCrítica (9.8)0.75%—Hotel Management System Project Hotel Management System9/2/202417/6/2026
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
ModificadaCrítica (9.8)0.73%—Hotel Management System Project Hotel Management System9/2/202417/6/2026
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
ModificadaCrítica (9.8)0.73%—Hotel Management System Project Hotel Management System9/2/202417/6/2026
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
AnalizadaMedia (5.4)0.37%—Jayesh Hotel Management System20/12/202317/6/2026
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
AnalizadaMedia (5.4)0.38%—Jayesh Hotel Management System20/12/202317/6/2026
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
AnalizadaMedia (5.4)0.38%—Jayesh Hotel Management System20/12/202317/6/2026
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
AnalizadaMedia (5.4)0.37%—Jayesh Hotel Management System20/12/202317/6/2026
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
ModificadaCrítica (9.8)0.62%—Mava Hotel Management System5/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.
ModificadaCrítica (9.8)0.86%—Online Hotel Management System Project Online Hotel Management System29/6/202317/6/2026
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection.
ModificadaMedia (6.1)0.66%—Online Hotel Management System Project Online Hotel Management System29/6/202317/6/2026
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box.
ModificadaMedia (5.4)0.45%—Hotel Management System Project Hotel Management System13/1/202317/6/2026
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
ModificadaMedia (6.5)0.71%—Hotel Management System Project Hotel Management System13/1/202317/6/2026
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
ModificadaMedia (5.4)0.76%—Hotel Management System Project Hotel Management System12/9/202217/6/2026
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".
ModificadaAlta (8.8)0.55%—Rigatur Online Booking AND Hotel Management System5/8/202217/6/2026
A vulnerability was found in Rigatur Online Booking and Hotel Management System aff6409. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Request Handler. The manipulation of the argument email/pass leads to sql injection. The…
ModificadaMedia (5.4)0.59%—Hotel Management System Project Hotel Management System12/7/202217/6/2026
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown function of the file /ci_hms/massage_room/edit/1 of the component Room Edit Page. The manipulation of the argument massageroomDetails with the input "><script>alert("XSS")</script> leads to…
ModificadaMedia (5.4)0.67%—Hotel Management System Project Hotel Management System12/7/202217/6/2026
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting.…
Orbitaley — Vulnerabilidades