Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.64% | — | WIN MEN International Travel Agency Management SystemAI | 11/8/2026 | 26/8/2026 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Travel AgencyAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Agency: from n/a through <= 1.5.5. | |
| Analizada | Baja (2.1) | 0.36% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be launched remotely.… | |
| Analizada | Baja (2) | 0.38% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Baja (2.1) | 0.38% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to… | |
| Modificada | Alta (8.8) | 0.21% | — | Rarathemes Travel Agency | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through <= 1.4.9. | |
| Modificada | Alta (7.2) | 1.5% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php. | |
| Modificada | Media (4.8) | 0.64% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php. | |
| Modificada | Alta (7.2) | 1.5% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php. |