Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.30% | — | Hcltech Traveler | 3/4/2025 | 17/6/2026 | HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests. | |
| Aplazada | Alta (7.6) | 0.25% | — | Shinetheme TravelerAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Shinetheme TravelerAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. | |
| Aplazada | Crítica (9) | 0.42% | — | Shinetheme TravelerAI | 27/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. | |
| Aplazada | Alta (8.2) | 0.36% | — | Shinetheme TravelerAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. | |
| Analizada | Media (6.1) | 0.25% | — | Shinecommerce Traveler | 15/3/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Crítica (9.8) | 0.67% | — | Shinecommerce Traveler | 15/3/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any… | |
| Aplazada | Alta (8.8) | 0.76% | — | TravelerAI | 28/2/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP… | |
| Aplazada | Alta (8.5) | 0.37% | — | Shinetheme Traveler CodeAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.3. | |
| Aplazada | Crítica (9) | 0.38% | — | Shinetheme Traveler CodeAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.2. | |
| Aplazada | Media (5.4) | 0.30% | — | Shinetheme Traveler Layout Essential FOR ElementorAI | 3/2/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4. | |
| Analizada | Media (5.3) | 0.26% | — | Hcltech Traveler FOR Microsoft Outlook | 12/11/2024 | 17/6/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways. | |
| Analizada | Alta (7.5) | 0.21% | — | Hcltech Traveler FOR Microsoft Outlook | 26/9/2024 | 17/6/2026 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. | |
| Aplazada | Media (6.5) | 0.33% | — | Camille Verrier Travelers MAPAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille Verrier Travelers' Map allows Stored XSS.This issue affects Travelers' Map: from n/a through 2.2.0. | |
| Modificada | Media (5.5) | 0.18% | — | Hcltech Traveler TO DO | 11/8/2023 | 17/6/2026 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. | |
| Modificada | Media (5.5) | 0.18% | — | Hcltech Traveler Companion | 11/8/2023 | 17/6/2026 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. | |
| Modificada | Media (4.3) | 0.41% | — | Hcltech Traveler TO DO | 11/8/2023 | 17/6/2026 | If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved. | |
| Modificada | Media (4.8) | 0.45% | — | Hcltech Traveler | 15/9/2022 | 17/6/2026 | There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf). | |
| Modificada | Media (4.8) | 0.38% | — | Hcltech Traveler | 1/6/2022 | 17/6/2026 | HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive… | |
| Modificada | Baja (3.9) | 0.16% | — | Hcltech Traveler Companion | 25/10/2021 | 17/6/2026 | "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK" | |
| Modificada | Baja (3.9) | 0.23% | — | Hcltech Traveler Companion | 21/10/2021 | 17/6/2026 | "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK" | |
| Modificada | Media (5.4) | 0.52% | — | Hcltech Traveler | 18/10/2019 | 17/6/2026 | HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the… | |
| Modificada | Alta (8.1) | 2.1% | — | IBM Traveler | 17/7/2016 | 17/6/2026 | IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Notes Traveler Companion | 2/3/2015 | 17/6/2026 | The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a… | |
| Modificada | Media (5) | 1.9% | — | IBM Notes Traveler | 4/11/2014 | 17/6/2026 | The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS. |