Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.44% | — | Fantasticlbp Hotels Server | 28/12/2025 | 17/6/2026 | A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is some unknown functionality of the file /controller/api/Room.php. Such manipulation of the argument hotelId leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.5) | 0.45% | — | Fantasticlbp Hotels Server | 15/12/2025 | 17/6/2026 | A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the argument pickedHotelName/type causes sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Media (5.5) | 0.42% | — | Fantasticlbp Hotels Server | 15/12/2025 | 17/6/2026 | A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql injection. The attack can be executed remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.1) | 0.24% | — | Fantasticlbp Hotels ServerAI | 15/11/2025 | 17/6/2026 | A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The manipulation of the argument subjectId/cityName results in sql injection. The attack can be executed remotely. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Hotels Server Project Hotels Server | 17/2/2023 | 17/6/2026 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Hotels Server Project Hotels Server | 10/5/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php". | |
| Modificada | Crítica (9.8) | 1.1% | — | Hotels Server Project Hotels Server | 17/2/2019 | 17/6/2026 | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled. | |
| Modificada | Alta (7.5) | 0.94% | — | Hotels Server Project Hotels Server | 8/2/2019 | 17/6/2026 | controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage. | |
| Modificada | Crítica (9.8) | 1.0% | — | Hotels Server Project Hotels Server | 20/1/2019 | 17/6/2026 | Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. |