Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.6)0.23%—Digitaldruid HoteldruidAI14/9/202622/9/2026
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
ModificadaCrítica (9.8)1.1%—Apache Druid10/2/202617/6/2026
Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty…
AnalizadaMedia (6.1)0.27%—Digitaldruid Hoteldruid11/12/202517/6/2026
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
AnalizadaCrítica (9.8)0.61%—Apache Druid26/11/202517/6/2026
Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-graphically secure random number generator. This may allow an…
ModificadaAlta (7.5)0.57%—Digitaldruid Hoteldruid20/6/20259/7/2026
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator…
AnalizadaMedia (6.1)0.34%—Digitaldruid Hoteldruid22/4/202517/6/2026
A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.
AnalizadaMedia (5.8)1.8%—Apache Druid20/3/202517/6/2026
Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management…
AnalizadaAlta (7.1)0.65%—Digitaldruid Hoteldruid11/3/202517/6/2026
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
AnalizadaAlta (7.3)0.42%—Digitaldruid Hoteldruid11/3/202517/6/2026
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is…
AnalizadaMedia (5.4)0.55%—Digitaldruid Hoteldruid11/3/202517/6/2026
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
ModificadaMedia (6.5)0.63%—Apache Druid17/9/202417/6/2026
Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows administrators to configure a list of allowed properties that users are able to provide for their JDBC…
ModificadaMedia (5.3)0.82%—Apache Druid17/9/202417/6/2026
Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j…
ModificadaAlta (7.5)0.40%—Digitaldruid Hoteldruid30/7/202417/6/2026
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
ModificadaMedia (6.1)0.70%—Digitaldruid Hoteldruid10/11/202317/6/2026
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
ModificadaMedia (5.4)0.49%—Digitaldruid Hoteldruid20/9/202317/6/2026
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
ModificadaMedia (5.4)0.49%—Digitaldruid Hoteldruid20/9/202317/6/2026
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.
ModificadaCrítica (9.8)0.73%—Digitaldruid Hoteldruid20/9/202317/6/2026
Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.
ModificadaCrítica (9.8)3.7%—Digitaldruid Hoteldruid20/9/202317/6/2026
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
ModificadaCrítica (9.8)4.2%—Digitaldruid Hoteldruid20/9/202317/6/2026
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
ModificadaCrítica (9.8)1.1%—Digitaldruid Hoteldruid20/9/202317/6/2026
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
ModificadaMedia (5.4)1.4%—Digitaldruid Hoteldruid13/6/202317/6/2026
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
ModificadaAlta (8.8)1.5%—Digitaldruid Hoteldruid13/6/202317/6/2026
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
ModificadaMedia (5.4)0.66%—Digitaldruid Hoteldruid3/5/202317/6/2026
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
ModificadaBaja (3.7)0.85%—Digitaldruid Hoteldruid16/9/202217/6/2026
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
ModificadaCrítica (9.8)7.3%—Digitaldruid Hoteldruid16/9/202217/6/2026
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.