Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.9% | 💥 Exploit | Vercot Serva32 | 20/5/2013 | 16/6/2026 | Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Jforjoomla COM Jreservation | 23/9/2009 | 16/6/2026 | SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php. | |
| Modificada | Media (4.3) | 0.93% | — | Webformatique Reservation Manager | 3/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Reservation Manager allows remote attackers to inject arbitrary web script or HTML via the resman_startdate parameter. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Funscripts RED Reservations | 2/4/2009 | 16/6/2026 | The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Enthrallweb Ereservations | 22/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM 5starhotelsJoomlahbs COM AllhotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained… | |
| Modificada | Alta (9.3) | 6.7% | — | Componentone SizeroneSAP GUISAP TaboneServantix Tsc2 Help Desk | 8/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomlahbs Hotel Booking Reservation System | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Joomlahbs COM TophotelmoduleJoomlahbs Hotel Booking Reservation System | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Softacid Hotel Reservation System | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Softacid Hotel Reservation System Multi | 24/7/2008 | 16/6/2026 | SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Loris Hotel Reservation System | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (10) | 2.9% | — | BUG Software Bughotel Reservation System | 16/11/2007 | 16/6/2026 | Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 43% | 💥 Exploit | Altap Portable Executable ViewerAltap Servant Salamander | 21/6/2007 | 16/6/2026 | Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file. | |
| Modificada | Media (5) | 1.8% | — | Sabre Desktop Reservation Software | 28/10/2002 | 16/6/2026 | The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001. |