Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.30%—Hcltech Traveler3/4/202517/6/2026
HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.
AplazadaAlta (7.6)0.25%—Shinetheme TravelerAI27/3/202517/6/2026
Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
AplazadaCrítica (9.3)0.34%—Shinetheme TravelerAI27/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
AplazadaCrítica (9)0.42%—Shinetheme TravelerAI27/3/202517/6/2026
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
AplazadaAlta (8.2)0.36%—Shinetheme TravelerAI27/3/202517/6/2026
Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
AnalizadaMedia (6.1)0.25%—Shinecommerce Traveler15/3/202517/6/2026
The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if…
AnalizadaCrítica (9.8)0.67%—Shinecommerce Traveler15/3/202517/6/2026
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any…
AplazadaAlta (8.8)0.76%—TravelerAI28/2/202517/6/2026
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP…
AplazadaAlta (8.5)0.37%—Shinetheme Traveler CodeAI4/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.3.
AplazadaCrítica (9)0.38%—Shinetheme Traveler CodeAI4/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.2.
AplazadaMedia (5.4)0.30%—Shinetheme Traveler Layout Essential FOR ElementorAI3/2/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4.
AnalizadaMedia (5.3)0.26%—Hcltech Traveler FOR Microsoft Outlook12/11/202417/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
AnalizadaAlta (7.5)0.21%—Hcltech Traveler FOR Microsoft Outlook26/9/202417/6/2026
The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.
AplazadaMedia (6.5)0.33%—Camille Verrier Travelers MAPAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille Verrier Travelers' Map allows Stored XSS.This issue affects Travelers' Map: from n/a through 2.2.0.
ModificadaMedia (5.5)0.18%—Hcltech Traveler TO DO11/8/202317/6/2026
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
ModificadaMedia (5.5)0.18%—Hcltech Traveler Companion11/8/202317/6/2026
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.
ModificadaMedia (4.3)0.41%—Hcltech Traveler TO DO11/8/202317/6/2026
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
ModificadaMedia (4.8)0.45%—Hcltech Traveler15/9/202217/6/2026
There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
ModificadaMedia (4.8)0.38%—Hcltech Traveler1/6/202217/6/2026
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive…
ModificadaBaja (3.9)0.16%—Hcltech Traveler Companion25/10/202117/6/2026
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
ModificadaBaja (3.9)0.23%—Hcltech Traveler Companion21/10/202117/6/2026
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
ModificadaMedia (5.4)0.52%—Hcltech Traveler18/10/201917/6/2026
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the…
ModificadaAlta (8.1)2.1%—IBM Traveler17/7/201617/6/2026
IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
ModificadaMedia (4.3)1.8%—IBM Notes Traveler Companion2/3/201517/6/2026
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a…
ModificadaMedia (5)1.9%—IBM Notes Traveler4/11/201417/6/2026
The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.
Orbitaley — Vulnerabilidades