Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Mayurik Online Tour & Travel Management System | 14/8/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/approve_user.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.42% | — | Mayurik Online Tour & Travel Management System | 14/8/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/disapprove_user.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.42% | — | Mayurik Online Tour & Travel Management System | 14/8/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.42% | — | Mayurik Online Tour & Travel Management System | 14/8/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/tax.php. The manipulation of the argument tname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.68% | — | Fabian Travel Management System | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This issue affects some unknown processing of the file /enquiry.php. The manipulation of the argument pid/t1/t2/t3/t4/t5/t6/t7 leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Media (5.3) | 0.40% | — | Code-projects Travel Management System | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /subcat.php. The manipulation of the argument catid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.45% | — | Code-projects Travel Management System | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Travel Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /package.php. The manipulation of the argument subcatid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.61% | — | Code-projects Travel Management System | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Travel Management System 1.0. It has been classified as critical. This affects an unknown part of the file /detail.php. The manipulation of the argument pid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.1) | 0.38% | — | Projectworlds Travel Management System | 4/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter. | |
| Analizada | Crítica (9.8) | 0.80% | — | Projectworlds Travel Management System | 4/11/2024 | 17/6/2026 | SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields. | |
| Analizada | Alta (7.5) | 0.90% | — | Projectworlds Travel Management System | 4/11/2024 | 17/6/2026 | SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php. | |
| Modificada | Media (6.1) | 0.61% | — | Cowell Enterprise Travel Management System Project Cowell Enterprise Travel Management System | 28/9/2022 | 17/6/2026 | Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack. | |
| Modificada | Crítica (9.8) | 1.9% | — | Travel Management System Project Travel Management System | 23/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Travel Management System Project Travel Management System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php. | |
| Modificada | Media (6.1) | 1.5% | — | Projectworlds Travel Management System | 17/5/2021 | 17/6/2026 | XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field | |
| Modificada | Crítica (9.8) | 3.7% | — | Projectworlds Travel Management System | 27/8/2020 | 17/6/2026 | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution. |