Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.17% | — | Magepeople WptravellyAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through 2.3.1. | |
| Aplazada | Alta (7.5) | 0.58% | — | Wptravelengine WP Travel EngineAI | 22/9/2026 | 22/9/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and… | |
| Aplazada | Alta (7.3) | 0.40% | — | Wensolutions WP TravelAI | 10/9/2026 | 21/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3. | |
| Aplazada | Media (5.3) | 0.22% | — | Wensolutions WP TravelAI | 9/9/2026 | 9/9/2026 | The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking. | |
| Aplazada | Baja (3.7) | 0.19% | — | Wptravelengine WP TravelAI | 9/9/2026 | 9/9/2026 | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it. | |
| Aplazada | Baja (3.7) | 0.19% | — | Wensolutions WP TravelAI | 9/9/2026 | 9/9/2026 | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state… | |
| Aplazada | Baja (3.5) | 0.28% | — | Apple MailAIApple CalendarAIApple ContactsAIHCL TravelerAI | 26/8/2026 | 28/8/2026 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the… | |
| Aplazada | Alta (7.5) | 0.69% | — | Wptravelengine WP Travel EngineAI | 16/8/2026 | 20/8/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 0.38% | — | Travelfic ToolkitAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | Wptravelengine WP Travel EngineAI | 12/8/2026 | 26/8/2026 | The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information,… | |
| Aplazada | Crítica (9.3) | 0.64% | — | WIN MEN International Travel Agency Management SystemAI | 11/8/2026 | 26/8/2026 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (5.3) | 0.16% | — | Wptravelengine WP Travel EngineAI | 6/8/2026 | 26/8/2026 | The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using… | |
| Aplazada | Media (4.3) | 0.27% | — | Wensolutions WP TravelAI | 30/7/2026 | 30/7/2026 | The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier. | |
| Aplazada | Media (5.3) | 0.30% | — | Wensolutions WP TravelAI | 30/7/2026 | 30/7/2026 | The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen… | |
| Aplazada | Alta (7.5) | 0.36% | — | Wptravelengine WP Travel EngineAI | 30/7/2026 | 30/7/2026 | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the… | |
| Aplazada | Alta (7.5) | 0.42% | — | Byteflows Travel & Hotel BookingAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Wensolutions WP TravelAI | 20/7/2026 | 20/7/2026 | The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site. | |
| Aplazada | Media (6.5) | 0.16% | — | HCL Traveler FOR Microsoft OutlookAI | 17/7/2026 | 17/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Aplazada | Media (4.6) | 0.24% | — | Wptravelengine WP Travel EngineAI | 7/7/2026 | 9/7/2026 | The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image… | |
| Aplazada | Alta (7.7) | 0.80% | — | Openwrt Luci-app-travelmateAIOpenwrt TravelmateAI | 2/7/2026 | 28/8/2026 | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only… | |
| Aplazada | Alta (7.1) | 0.25% | — | Trendy TravelAI | 2/7/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. | |
| Analizada | Alta (7.8) | 0.27% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 6/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party… | |
| Analizada | Media (5.5) | 0.15% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 29/9/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application. | |
| Analizada | Alta (7.8) | 0.09% | — | Hcltech Traveler FOR Microsoft Outlook | 26/6/2026 | 1/10/2026 | The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Travel BookingAI | 26/6/2026 | 26/6/2026 | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. |