Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.36% | — | SAP MY Travel RequestsAI | 14/5/2024 | 17/6/2026 | SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and… | |
| Aplazada | Media (4.3) | 0.21% | — | Magepeople WptravellyAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0. | |
| Modificada | Alta (7.2) | 0.57% | — | Wptravelengine WP Travel Engine | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Wptravelengine WP Travel Engine | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9. | |
| Aplazada | Media (6.5) | 0.33% | — | Camille Verrier Travelers MAPAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille Verrier Travelers' Map allows Stored XSS.This issue affects Travelers' Map: from n/a through 2.2.0. | |
| Analizada | Media (6.1) | 0.89% | 💥 Exploit | Travelpayouts | 20/3/2024 | 17/6/2026 | The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick… | |
| Analizada | Alta (7.2) | 0.64% | — | Mayurik Online Tours & Travels Management System | 4/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/operations/expense_category.php of the component HTTP POST Request Handler. The manipulation of the argument status leads to sql injection. It… | |
| Modificada | Media (6.1) | 0.48% | 💥 PoC | Remyandrade Travel Journal Using PHP AND Mysql With Source Code | 1/2/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php. | |
| Modificada | Media (6.1) | 0.46% | — | Remyandrade Travel Journal Using PHP AND Mysql With Source Code | 1/2/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php. | |
| Modificada | Crítica (9.8) | 0.63% | — | Mayurik Online Tours &travels Management System | 25/1/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec of the file payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.65% | — | Mayurik Online Tours & Travels Management System | 25/1/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare of the file admin/pay.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.70% | — | Mayurik Online Tours & Travels Management System | 19/1/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. Affected by this issue is the function exec of the file admin/operations/expense.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.74% | — | Mayurik Online Tours & Travels Management System | 13/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (6.1) | 0.36% | — | Travelmap | 27/9/2023 | 17/6/2026 | Unauth. Cross-Site Scripting (XSS) vulnerability in TravelMap plugin <= 1.0.1 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Tours & Travels Management System Project Online Tours & Travels Management System | 10/9/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. This issue affects the function exec of the file booking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.62% | — | Coyavtravel Proagent | 5/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 . | |
| Modificada | Alta (7.2) | 1.5% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php. |