Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.53% | — | Thimpress WP Hotel Booking | 4/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9. | |
| Analizada | Media (5.3) | 0.53% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload of the file /guest/update.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.44% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/mod_room/controller.php. The manipulation of the argument id leads to sql injection. It… | |
| Analizada | Media (5.3) | 1.2% | 💥 PoC | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely.… | |
| Analizada | Alta (8.8) | 18% | — | Thimpress WP Hotel Booking | 2/10/2024 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the… | |
| Analizada | Media (5.4) | 0.29% | — | Webdzier Hotel Galaxy | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through 4.4.24. | |
| Analizada | Media (6.9) | 0.65% | — | Fabian Responsive Hotel Site | 27/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument name/phone/email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.1) | 0.48% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section. | |
| Analizada | Alta (7.2) | 0.58% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php. | |
| Analizada | Alta (7.2) | 0.53% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php. | |
| Analizada | Crítica (9.1) | 0.48% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access. | |
| Analizada | Alta (7.5) | 0.41% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section. | |
| Analizada | Alta (7.5) | 0.48% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section. | |
| Analizada | Media (6.8) | 0.18% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php. | |
| Analizada | Media (4.8) | 0.45% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter. | |
| Analizada | Media (4.7) | 0.51% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter. | |
| Analizada | Media (6.1) | 0.47% | — | Jayesh Hotel Management System | 22/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Hotel Management SystemAI | 20/8/2024 | 17/6/2026 | An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password. | |
| Analizada | Crítica (9.8) | 0.72% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php. | |
| Analizada | Alta (8.8) | 0.34% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |
| Analizada | Crítica (9.8) | 0.74% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php. | |
| Analizada | Alta (8.8) | 0.30% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.58% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php. | |
| Analizada | Alta (8.8) | 0.31% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |
| Analizada | Alta (8.6) | 0.53% | — | Vaibhavverma9999 Hotel Management System | 20/8/2024 | 17/6/2026 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php. |