Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%💥 ExploitBookingcentre Booking System FOR Hotels Group22/12/200916/6/2026
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors.
ModificadaAlta (7.5)1.00%💥 ExploitBookingcentre Booking System FOR Hotels Group18/5/200916/6/2026
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.98%💥 ExploitBookingcentre Booking System FOR Hotels Group18/5/200916/6/2026
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter.
ModificadaAlta (7.5)2.0%💥 ExploitInterguias Nethoteles20/4/200916/6/2026
SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL commands via the id_establecimiento parameter.
ModificadaAlta (7.5)1.4%💥 ExploitBookingcentre Booking System FOR Hotels Group20/2/200916/6/2026
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
ModificadaMedia (4.3)1.7%💥 ExploitBookingcentre Booking System FOR Hotels Group20/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM 5starhotelsJoomlahbs COM AllhotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained…
ModificadaAlta (7.5)1.0%💥 ExploitJoomlahbs Hotel Booking Reservation System6/1/200916/6/2026
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)2.0%💥 ExploitJoomlahbs COM TophotelmoduleJoomlahbs Hotel Booking Reservation System6/1/200916/6/2026
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitBdigital WEB Solutions Webstudio Ehotel1/12/200816/6/2026
SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitSoftacid Hotel Reservation System24/9/200816/6/2026
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
ModificadaAlta (7.5)2.4%💥 ExploitSoftacid Hotel Reservation System Multi24/7/200816/6/2026
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter.
ModificadaAlta (7.5)0.97%💥 ExploitMole Group Hotel Script10/7/200816/6/2026
SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter.
ModificadaMedia (5)7.3%💥 ExploitRemotelyanywhere10/3/200816/6/2026
The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of service (crash) via an invalid Accept-Charset header, which triggers a NULL pointer dereference. NOTE: the service is automatically restarted.
ModificadaMedia (4.3)0.84%—Loris Hotel Reservation System14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects.com PRE Hotels & Resorts Management System13/2/200816/6/2026
SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page.
ModificadaMedia (6.4)2.1%💥 ExploitPrenotazioni ON Line Syshotel ON Line System9/1/200816/6/2026
Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.
ModificadaAlta (10)2.9%—BUG Software Bughotel Reservation System16/11/200716/6/2026
Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.