Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.47% | — | Travel BookingAI | 18/12/2024 | 17/6/2026 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (6.5) | 0.28% | — | Wensolutions WP TravelAI | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 9.6.0. | |
| Aplazada | Alta (7.1) | 0.17% | — | Thomas Hoefter Simple Travel MAPAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Simple Travel Map simple-travel-map allows Stored XSS.This issue affects Simple Travel Map: from n/a through <= 0.1. | |
| Analizada | Media (4.3) | 0.30% | — | Wptravelengine WP Travel Engine | 23/11/2024 | 17/6/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpte_onboard_save_function_callback() function in all versions up to, and including, 6.2.1. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.26% | — | Hcltech Traveler FOR Microsoft Outlook | 12/11/2024 | 17/6/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways. | |
| Analizada | Baja (2.3) | 0.45% | — | Mariazevedo88 Travels-java-api | 6/11/2024 | 17/6/2026 | A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the component JWT Secret… | |
| Analizada | Media (6.1) | 0.38% | — | Projectworlds Travel Management System | 4/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter. | |
| Analizada | Crítica (9.8) | 0.80% | — | Projectworlds Travel Management System | 4/11/2024 | 17/6/2026 | SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields. | |
| Analizada | Alta (7.5) | 0.90% | — | Projectworlds Travel Management System | 4/11/2024 | 17/6/2026 | SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php. | |
| Aplazada | Alta (7.5) | 0.56% | — | Magepeople WptravellyAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7. | |
| Analizada | Crítica (9.8) | 0.53% | — | Mayurik Online Tours & Travels Management System | 15/10/2024 | 17/6/2026 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php. | |
| Aplazada | Media (5.9) | 0.31% | — | Wensolutions WP TravelAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from n/a through <= 9.3.1. | |
| Aplazada | Media (6.5) | 0.26% | — | WP Travel Gutenberg BlocksAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel Gutenberg Blocks wp-travel-blocks allows Stored XSS.This issue affects WP Travel Gutenberg Blocks: from n/a through <= 3.6.0. | |
| Analizada | Media (5.4) | 0.29% | — | Mayurik Online Tours AND Travels Management System | 4/10/2024 | 17/6/2026 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php. | |
| Analizada | Alta (7.5) | 0.21% | — | Hcltech Traveler FOR Microsoft Outlook | 26/9/2024 | 17/6/2026 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. | |
| Aplazada | Alta (8) | 1.3% | — | Gigastone TR1 Travel Router R101AI | 25/9/2024 | 17/6/2026 | Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request. | |
| Aplazada | Media (6.5) | 0.25% | — | WP Travel Gutenberg BlocksAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Stored XSS.This issue affects WP Travel Gutenberg Blocks: from n/a through 3.5.1. | |
| Analizada | Media (5.4) | 0.28% | — | Wptravelengine WP Travel Engine | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Travel Engine allows Stored XSS.This issue affects WP Travel Engine: from n/a through 5.9.1. | |
| Modificada | Alta (8.8) | 0.44% | — | Themeenergy Book Your Travel | 9/7/2024 | 17/6/2026 | Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects BookYourTravel: from n/a through 8.18.17. | |
| Modificada | Media (5.3) | 0.60% | — | Mayurik Online Tours & Travels Management System | 3/7/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Media (4.6) | 0.29% | — | Talyabilisim Travel Apps | 27/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Travel APPS: before v17.0.68. | |
| Modificada | Crítica (9.8) | 0.47% | — | Talyabilisim Travel Apps | 27/6/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Travel APPS: before v17.0.68. | |
| Analizada | Media (5.3) | 0.34% | — | Wptravelengine WP Travel Engine | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.8.0. | |
| Aplazada | Media (5.3) | 0.39% | — | WptravellyAI | 29/5/2024 | 17/6/2026 | The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to… |