Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.36%—SAP MY Travel RequestsAI14/5/202417/6/2026
SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and…
AplazadaMedia (4.3)0.21%—Magepeople WptravellyAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0.
ModificadaAlta (7.2)0.57%—Wptravelengine WP Travel Engine29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
ModificadaCrítica (9.8)2.2%💥 ExploitWptravelengine WP Travel Engine29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
AplazadaMedia (6.5)0.33%—Camille Verrier Travelers MAPAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille Verrier Travelers' Map allows Stored XSS.This issue affects Travelers' Map: from n/a through 2.2.0.
AnalizadaMedia (6.1)0.89%💥 ExploitTravelpayouts20/3/202417/6/2026
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick…
AnalizadaAlta (7.2)0.64%—Mayurik Online Tours & Travels Management System4/3/202417/6/2026
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/operations/expense_category.php of the component HTTP POST Request Handler. The manipulation of the argument status leads to sql injection. It…
ModificadaMedia (6.1)0.48%💥 PoCRemyandrade Travel Journal Using PHP AND Mysql With Source Code1/2/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.
ModificadaMedia (6.1)0.46%—Remyandrade Travel Journal Using PHP AND Mysql With Source Code1/2/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
ModificadaCrítica (9.8)0.63%—Mayurik Online Tours &travels Management System25/1/202417/6/2026
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec of the file payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.65%—Mayurik Online Tours & Travels Management System25/1/202417/6/2026
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare of the file admin/pay.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.70%—Mayurik Online Tours & Travels Management System19/1/202417/6/2026
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. Affected by this issue is the function exec of the file admin/operations/expense.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.74%—Mayurik Online Tours & Travels Management System13/12/202317/6/2026
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (6.1)0.36%—Travelmap27/9/202317/6/2026
Unauth. Cross-Site Scripting (XSS) vulnerability in TravelMap plugin <= 1.0.1 versions.
ModificadaCrítica (9.8)0.74%—Online Tours & Travels Management System Project Online Tours & Travels Management System10/9/202317/6/2026
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. This issue affects the function exec of the file booking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.62%—Coyavtravel Proagent5/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .
ModificadaAlta (7.2)1.5%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.