Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)8.9%💥 ExploitVercot Serva3220/5/201316/6/2026
Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request.
ModificadaAlta (7.5)1.0%💥 ExploitJforjoomla COM Jreservation23/9/200916/6/2026
SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.
ModificadaMedia (4.3)0.93%—Webformatique Reservation Manager3/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Reservation Manager allows remote attackers to inject arbitrary web script or HTML via the resman_startdate parameter.
ModificadaMedia (5)2.2%💥 ExploitFunscripts RED Reservations2/4/200916/6/2026
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.
ModificadaAlta (7.5)1.0%💥 ExploitEnthrallweb Ereservations22/1/200916/6/2026
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM 5starhotelsJoomlahbs COM AllhotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained…
ModificadaAlta (9.3)6.7%—Componentone SizeroneSAP GUISAP TaboneServantix Tsc2 Help Desk8/1/200916/6/2026
Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and…
ModificadaAlta (7.5)1.0%💥 ExploitJoomlahbs Hotel Booking Reservation System6/1/200916/6/2026
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)2.0%💥 ExploitJoomlahbs COM TophotelmoduleJoomlahbs Hotel Booking Reservation System6/1/200916/6/2026
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitSoftacid Hotel Reservation System24/9/200816/6/2026
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
ModificadaAlta (7.5)2.4%💥 ExploitSoftacid Hotel Reservation System Multi24/7/200816/6/2026
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter.
ModificadaMedia (4.3)0.84%—Loris Hotel Reservation System14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (10)2.9%—BUG Software Bughotel Reservation System16/11/200716/6/2026
Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)43%💥 ExploitAltap Portable Executable ViewerAltap Servant Salamander21/6/200716/6/2026
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.
ModificadaMedia (5)1.8%—Sabre Desktop Reservation Software28/10/200216/6/2026
The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.
Orbitaley — Vulnerabilidades