Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%💥 ExploitJoomlahbs COM TophotelmoduleJoomlahbs Hotel Booking Reservation System6/1/200916/6/2026
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)0.99%💥 ExploitDeeserver Panuwat Promoteweb Mysql14/11/200816/6/2026
SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)0.91%💥 ExploitDeeserver Ultimate Webboard22/10/200816/6/2026
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter.
ModificadaAlta (10)6.8%💥 ExploitEtype Eserv15/10/200816/6/2026
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to the ABOR command.
ModificadaAlta (7.5)0.97%💥 ExploitSoftacid Hotel Reservation System24/9/200816/6/2026
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.
ModificadaAlta (7.5)2.4%💥 ExploitSoftacid Hotel Reservation System Multi24/7/200816/6/2026
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter.
ModificadaAlta (7.5)1.0%💥 ExploitCogites E Reserve27/4/200816/6/2026
SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.
ModificadaMedia (5)1.3%—Omegasoft Interneserviceslosungen4/3/200816/6/2026
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames.
ModificadaMedia (6.4)2.2%💥 ExploitOmegasoft Interneserviceslosungen4/3/200816/6/2026
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.
ModificadaMedia (4.3)0.84%—Loris Hotel Reservation System14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (10)2.9%—BUG Software Bughotel Reservation System16/11/200716/6/2026
Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.3%—Omegasoft Interneserviceslosungen4/6/200716/6/2026
Multiple SQL injection vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to execute arbitrary SQL commands via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields.
ModificadaMedia (4.3)1.3%—Omegasoft Interneserviceslosungen4/6/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in OmegaMw7.asp in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow remote attackers to inject arbitrary web script or HTML via (1) user-created text fields; the (2) F05003, (3) F05005, and (4) F05015 fields; and other unspecified standard fields.
ModificadaMedia (4)1.6%—Etype Eserv2/6/200616/6/2026
The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests containing dot, space, and slash characters, which reveals the source code of script files.
ModificadaMedia (5.5)1.6%—Etype Eserv2/6/200616/6/2026
Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY…
ModificadaMedia (5.8)1.2%—Omegasoft Interneserviceslosungen30/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allows remote attackers to inject arbitrary web script or HTML via the WCE parameter.
ModificadaMedia (4.3)1.2%—PHP Lite Meeting Reserve28/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5)1.3%—Planetdns Planetfileserver6/7/200516/6/2026
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
ModificadaMedia (5)3.2%💥 ExploitLinbit Technologies Linbox Officeserver30/3/200416/6/2026
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).
ModificadaMedia (5)2.3%—Thomas Krebs Niteserver Ftpd31/12/200316/6/2026
Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.
ModificadaMedia (5)3.9%💥 ExploitEtype Eserv31/12/200316/6/2026
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
ModificadaAlta (10)7.0%—Perception Liteserve4/11/200316/6/2026
Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.
ModificadaMedia (5)7.8%💥 ExploitEtype Eserv16/6/200316/6/2026
Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.
ModificadaMedia (5)1.6%—Perception Liteserve31/12/200216/6/2026
Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.
ModificadaMedia (5)1.2%—Perception Liteserve31/12/200216/6/2026
Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.