Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.69% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.50% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.50% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.39% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch… | |
| Aplazada | Baja (2.1) | 0.37% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 19/9/2026 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Media (5.5) | 0.55% | — | Jaychouchannel Tourism-management-systemAI | 7/9/2026 | 8/9/2026 | A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName… | |
| Aplazada | Media (5.5) | 0.45% | — | Jaychouchannel Tourism Management SystemAI | 7/9/2026 | 8/9/2026 | A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument… | |
| Modificada | Media (5.5) | 0.38% | — | Phpgurukul Tourism Management System | 16/11/2025 | 30/9/2026 | A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Analizada | Alta (7.2) | 1.6% | 💥 Exploit | Sohamjuhin Tourism Management System | 10/9/2025 | 17/6/2026 | A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality. | |
| Analizada | Media (4.8) | 0.35% | — | Fabian Tourism Management System | 18/5/2025 | 17/6/2026 | A vulnerability was found in code-projects Tourism Management System 1.0 and classified as critical. This issue affects the function LoginUser of the component Login User. The manipulation of the argument username/password leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been… | |
| Analizada | Media (4.8) | 0.35% | — | Fabian Tourism Management System | 18/5/2025 | 17/6/2026 | A vulnerability has been found in code-projects Tourism Management System 1.0 and classified as critical. This vulnerability affects the function AddUser of the component User Registration. The manipulation of the argument username/password leads to buffer overflow. Local access is required to approach this attack.… | |
| Analizada | Media (5.3) | 0.38% | — | Fabian Tourism Management System | 17/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation of the argument pgedetails leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.54% | — | Phpgurukul Tourism Management System | 6/8/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter. | |
| Modificada | Alta (8.1) | 0.73% | — | Phpgurukul Tourism Management System | 16/4/2024 | 17/6/2026 | Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image. | |
| Analizada | Alta (8.8) | 0.76% | — | Phpgurukul Tourism Management System | 16/4/2024 | 17/6/2026 | Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image. | |
| Analizada | Media (6.1) | 0.42% | — | Phpgurukul Tourism Management System | 23/2/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Tourism Management System 1.0. Affected is an unknown function of the file user-bookings.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.3) | 0.45% | — | Phpgurukul Tourism Management System | 14/6/2022 | 17/6/2026 | Tourism Management System Version: V 3.2 is affected by: Cross Site Request Forgery (CSRF). | |
| Modificada | Alta (8.8) | 3.1% | — | Phpgurukul Tourism Management System | 17/11/2020 | 17/6/2026 | An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page. |