Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Free Hotel Reservation SystemAI | 27/3/2026 | 17/6/2026 | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Free Hotel Reservation SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available… | |
| Aplazada | Baja (2) | 0.38% | — | Itsourcecode Free Hotel Reservation SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /admin/mod_amenities/index.php?view=add. This manipulation of the argument image causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.52% | — | Wecodex Hotel CMS | 26/3/2026 | 17/6/2026 | Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Free Hotel Reservation SystemAI | 23/3/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument account_id leads to sql injection. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Free Hotel Reservation SystemAI | 16/3/2026 | 17/6/2026 | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a manipulation of the argument Home can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be… | |
| Aplazada | Alta (8.8) | 0.34% | — | Uhotelbooking SystemAI | 12/3/2026 | 17/6/2026 | uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection… | |
| Analizada | Media (5.5) | 0.59% | — | Itsourcecode Free Hotel Reservation System | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performing a manipulation of the argument amen_id/rmtype_id results in sql injection. The attack is possible to be carried out… | |
| Aplazada | Media (6.5) | 0.33% | — | Themewant Easy Hotel BookingAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in themewant Easy Hotel Booking easy-hotel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Hotel Booking: from n/a through <= 1.9.2. | |
| Aplazada | Baja (2.1) | 0.34% | — | Tushar-2223 Hotel-management-systemAI | 16/2/2026 | 17/6/2026 | A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /home.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Name/Email results in sql injection. The attack can be… | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.1) | 0.21% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods HotellerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Hoteller hoteller allows Reflected XSS.This issue affects Hoteller: from n/a through < 6.8.9. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2. | |
| Modificada | Alta (8.8) | 0.47% | — | Aida Hotel Guest Hotspot | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Modificada | Media (6.1) | 0.22% | — | Aida Hotel Guest Hotspot | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows Reflected XSS. This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did… | |
| Aplazada | Media (5.3) | 0.30% | — | Thimpress WP Hotel BookingAI | 17/1/2026 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for… | |
| Aplazada | Media (5.3) | 0.26% | — | Awesome Hotel BookingAI | 7/1/2026 | 17/6/2026 | The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification without capability checks. This makes it… | |
| Aplazada | Media (5.3) | 0.26% | — | Nicdark Hotel BookingAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in nicdark Hotel Booking nd-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Booking: from n/a through <= 3.8. | |
| Analizada | Media (5.5) | 0.44% | — | Fantasticlbp Hotels Server | 28/12/2025 | 7/10/2026 | A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is some unknown functionality of the file /controller/api/Room.php. Such manipulation of the argument hotelId leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.1) | 0.26% | — | Yohanawi Hotel Management System | 18/12/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php. | |
| Aplazada | Crítica (9.1) | 0.37% | — | Jetmonsters Motopress-hotel-booking-liteAI | 18/12/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3. | |
| Aplazada | Alta (8.8) | 0.36% | — | E-plugins Hotel ListingAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0. | |
| Analizada | Media (5.5) | 0.45% | — | Fantasticlbp Hotels Server | 15/12/2025 | 17/6/2026 | A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the argument pickedHotelName/type causes sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Media (5.5) | 0.42% | — | Fantasticlbp Hotels Server | 15/12/2025 | 17/6/2026 | A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql injection. The attack can be executed remotely. The exploit is now public and may… |