Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 22/12/2009 | 16/6/2026 | SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 18/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 18/5/2009 | 16/6/2026 | SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Interguias Nethoteles | 20/4/2009 | 16/6/2026 | SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL commands via the id_establecimiento parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Bookingcentre Booking System FOR Hotels Group | 20/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM 5starhotelsJoomlahbs COM AllhotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomlahbs Hotel Booking Reservation System | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Joomlahbs COM TophotelmoduleJoomlahbs Hotel Booking Reservation System | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Bdigital WEB Solutions Webstudio Ehotel | 1/12/2008 | 16/6/2026 | SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Softacid Hotel Reservation System | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Softacid Hotel Reservation System Multi | 24/7/2008 | 16/6/2026 | SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mole Group Hotel Script | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Remotelyanywhere | 10/3/2008 | 16/6/2026 | The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of service (crash) via an invalid Accept-Charset header, which triggers a NULL pointer dereference. NOTE: the service is automatically restarted. | |
| Modificada | Media (4.3) | 0.84% | — | Loris Hotel Reservation System | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects.com PRE Hotels & Resorts Management System | 13/2/2008 | 16/6/2026 | SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page. | |
| Modificada | Media (6.4) | 2.1% | 💥 Exploit | Prenotazioni ON Line Syshotel ON Line System | 9/1/2008 | 16/6/2026 | Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter. | |
| Modificada | Alta (10) | 2.9% | — | BUG Software Bughotel Reservation System | 16/11/2007 | 16/6/2026 | Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |