Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.64%—WIN MEN International Travel Agency Management SystemAI11/8/202626/8/2026
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
AplazadaMedia (5.3)0.29%—Rarathemes Travel AgencyAI13/3/202617/6/2026
Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Agency: from n/a through <= 1.5.5.
AnalizadaBaja (2.1)0.36%—Ashraf-kabir Travel-agency23/11/202517/6/2026
A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be launched remotely.…
AnalizadaBaja (2)0.38%—Ashraf-kabir Travel-agency23/11/202517/6/2026
A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be initiated remotely.…
ModificadaBaja (2.1)0.38%—Ashraf-kabir Travel-agency23/11/202517/6/2026
A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to…
ModificadaAlta (8.8)0.21%—Rarathemes Travel Agency2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through <= 1.4.9.
ModificadaAlta (7.2)1.5%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php.
ModificadaMedia (4.8)0.64%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php.
ModificadaAlta (7.2)1.5%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.
ModificadaAlta (7.2)1.3%—Online Travel Agency System Project Online Travel Agency System17/8/202317/6/2026
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php.
Orbitaley — Vulnerabilidades