Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.53%—Thimpress WP Hotel Booking4/11/202417/6/2026
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.
AnalizadaMedia (5.3)0.53%—Janobe Online Hotel Reservation System27/10/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload of the file /guest/update.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has…
AnalizadaMedia (5.3)0.44%—Janobe Online Hotel Reservation System27/10/202417/6/2026
A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/mod_room/controller.php. The manipulation of the argument id leads to sql injection. It…
AnalizadaMedia (5.3)1.2%💥 PoCJanobe Online Hotel Reservation System27/10/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely.…
AnalizadaAlta (8.8)18%—Thimpress WP Hotel Booking2/10/202417/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the…
AnalizadaMedia (5.4)0.29%—Webdzier Hotel Galaxy18/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webdzier Hotel Galaxy allows Stored XSS.This issue affects Hotel Galaxy: from n/a through 4.4.24.
AnalizadaMedia (6.9)0.65%—Fabian Responsive Hotel Site27/8/202417/6/2026
A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument name/phone/email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaCrítica (9.1)0.48%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.
AnalizadaAlta (7.2)0.58%—Jayesh Hotel Management System22/8/202417/6/2026
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
AnalizadaAlta (7.2)0.53%—Jayesh Hotel Management System22/8/202417/6/2026
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
AnalizadaCrítica (9.1)0.48%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.
AnalizadaAlta (7.5)0.41%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.
AnalizadaAlta (7.5)0.48%—Jayesh Hotel Management System22/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.
AnalizadaMedia (6.8)0.18%—Jayesh Hotel Management System22/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.
AnalizadaMedia (4.8)0.45%—Jayesh Hotel Management System22/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.
AnalizadaMedia (4.7)0.51%—Jayesh Hotel Management System22/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.
AnalizadaMedia (6.1)0.47%—Jayesh Hotel Management System22/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.
AplazadaCrítica (9.8)0.55%—Hotel Management SystemAI20/8/202417/6/2026
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.
AnalizadaCrítica (9.8)0.72%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
AnalizadaAlta (8.8)0.34%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaCrítica (9.8)0.74%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
AnalizadaAlta (8.8)0.30%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.58%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.
AnalizadaAlta (8.8)0.31%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
AnalizadaAlta (8.6)0.53%—Vaibhavverma9999 Hotel Management System20/8/202417/6/2026
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.
Orbitaley — Vulnerabilidades