Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-44203
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database …
Hoteldruid
Mitigation only
MEDIUM 6.1
CVE-2023-43378
A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec…
Hoteldruid
No fix yet
HIGH 7.3
CVE-2025-25748
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user p…
Hoteldruid
Mitigation only
MEDIUM 5.4
CVE-2025-25747
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information v…
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43373
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43374
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43375
Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giorn…
Hoteldruid
Mitigation only
MEDIUM 5.4
CVE-2023-43376
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML …
Hoteldruid
No fix yet
MEDIUM 5.4
CVE-2023-43377
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scr…
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43371
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
Hoteldruid
No fix yet
HIGH 8.8
CVE-2023-33817
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
Hoteldruid
No fix yet
MEDIUM 5.4
CVE-2023-34537
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick use…
Hoteldruid
No fix yet
MEDIUM 5.4
CVE-2023-29839
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands…
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2021-42949EPSS 6%
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to by…
Hoteldruid
Mitigation only
MEDIUM 6.1
CVE-2022-26564
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
Hoteldruid
No fix yet
HIGH 8.8
CVE-2022-22909EPSS 45%
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payloa…
Hoteldruid
No fix yet
MEDIUM 6.1
CVE-2021-38559
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2021-37832
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can …
Hoteldruid
No fix yet
MEDIUM 6.1
CVE-2021-37833
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitra…
Hoteldruid
No fix yet
MEDIUM 6.1
CVE-2019-8937EPSS 11%
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, an…
Hoteldruid
No fix yet