Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)18%—Thimpress WP Hotel Booking2/10/202417/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the…
AnalizadaMedia (5.4)0.29%—Webdzier Hotel Galaxy18/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through 4.4.24.
AnalizadaMedia (6.9)0.65%—Fabian Responsive Hotel Site27/8/202417/6/2026
A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument name/phone/email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaCrítica (9.1)0.48%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.
AnalizadaAlta (7.2)0.58%—Jayesh Hotel Management System22/8/202417/6/2026
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
AnalizadaAlta (7.2)0.53%—Jayesh Hotel Management System22/8/202417/6/2026
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
AnalizadaCrítica (9.1)0.48%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.
AnalizadaAlta (7.5)0.41%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.
AnalizadaAlta (7.5)0.48%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.
AnalizadaMedia (6.8)0.18%—Jayesh Hotel Management System22/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.
AnalizadaMedia (4.8)0.45%—Jayesh Hotel Management System22/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.
AnalizadaMedia (4.7)0.51%—Jayesh Hotel Management System22/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.
AnalizadaMedia (6.1)0.47%—Jayesh Hotel Management System22/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.
AplazadaCrítica (9.8)0.55%—Hotel Management SystemAI20/8/202417/6/2026
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.
AnalizadaCrítica (9.8)0.72%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
AnalizadaAlta (8.8)0.34%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaCrítica (9.8)0.74%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
AnalizadaAlta (8.8)0.30%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.58%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.
AnalizadaAlta (8.8)0.31%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaAlta (8.6)0.53%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.
ModificadaAlta (7.5)0.40%—Digitaldruid Hoteldruid30/7/202417/6/2026
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
ModificadaMedia (6.9)0.68%—Clive 21 Simple Online Hotel Reservation System25/6/202417/6/2026
A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)4.2%💥 ExploitThimpress WP Hotel Booking20/6/202417/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
ModificadaMedia (6.9)0.80%—Clive 21 Simple Online Hotel Reservation System18/6/202417/6/2026
A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file edit_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The…
Orbitaley — Vulnerabilidades