Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Joomlahbs COM TophotelmoduleJoomlahbs Hotel Booking Reservation System | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Deeserver Panuwat Promoteweb Mysql | 14/11/2008 | 16/6/2026 | SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Deeserver Ultimate Webboard | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter. | |
| Modificada | Alta (10) | 6.8% | 💥 Exploit | Etype Eserv | 15/10/2008 | 16/6/2026 | Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to the ABOR command. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Softacid Hotel Reservation System | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Softacid Hotel Reservation System Multi | 24/7/2008 | 16/6/2026 | SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cogites E Reserve | 27/4/2008 | 16/6/2026 | SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter. | |
| Modificada | Media (5) | 1.3% | — | Omegasoft Interneserviceslosungen | 4/3/2008 | 16/6/2026 | OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Media (6.4) | 2.2% | 💥 Exploit | Omegasoft Interneserviceslosungen | 4/3/2008 | 16/6/2026 | OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie. | |
| Modificada | Media (4.3) | 0.84% | — | Loris Hotel Reservation System | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (10) | 2.9% | — | BUG Software Bughotel Reservation System | 16/11/2007 | 16/6/2026 | Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | Omegasoft Interneserviceslosungen | 4/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. | |
| Modificada | Media (4.3) | 1.3% | — | Omegasoft Interneserviceslosungen | 4/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to inject arbitrary web script or HTML via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields. | |
| Modificada | Media (4) | 1.6% | — | Etype Eserv | 2/6/2006 | 16/6/2026 | The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests containing dot, space, and slash characters, which reveals the source code of script files. | |
| Modificada | Media (5.5) | 1.6% | — | Etype Eserv | 2/6/2006 | 16/6/2026 | Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY… | |
| Modificada | Media (5.8) | 1.2% | — | Omegasoft Interneserviceslosungen | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allows remote attackers to inject arbitrary web script or HTML via the WCE parameter. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Lite Meeting Reserve | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 1.3% | — | Planetdns Planetfileserver | 6/7/2005 | 16/6/2026 | mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Linbit Technologies Linbox Officeserver | 30/3/2004 | 16/6/2026 | LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash). | |
| Modificada | Media (5) | 2.3% | — | Thomas Krebs Niteserver Ftpd | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | Etype Eserv | 31/12/2003 | 16/6/2026 | The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data. | |
| Modificada | Alta (10) | 7.0% | — | Perception Liteserve | 4/11/2003 | 16/6/2026 | Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name. | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Etype Eserv | 16/6/2003 | 16/6/2026 | Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated. | |
| Modificada | Media (5) | 1.6% | — | Perception Liteserve | 31/12/2002 | 16/6/2026 | Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request. | |
| Modificada | Media (5) | 1.2% | — | Perception Liteserve | 31/12/2002 | 16/6/2026 | Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL. |