Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.44%—Fantasticlbp Hotels Server28/12/202517/6/2026
A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is some unknown functionality of the file /controller/api/Room.php. Such manipulation of the argument hotelId leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (5.5)0.45%—Fantasticlbp Hotels Server15/12/202517/6/2026
A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the argument pickedHotelName/type causes sql injection. The attack is possible to be carried out remotely. The…
AnalizadaMedia (5.5)0.42%—Fantasticlbp Hotels Server15/12/202517/6/2026
A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql injection. The attack can be executed remotely. The exploit is now public and may…
AplazadaBaja (2.1)0.24%—Fantasticlbp Hotels ServerAI15/11/202517/6/2026
A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The manipulation of the argument subjectId/cityName results in sql injection. The attack can be executed remotely. The…
ModificadaCrítica (9.8)0.82%—Hotels Server Project Hotels Server17/2/202317/6/2026
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
ModificadaMedia (6.1)1.2%—Hotels Server Project Hotels Server10/5/202117/6/2026
Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php".
ModificadaCrítica (9.8)1.1%—Hotels Server Project Hotels Server17/2/201917/6/2026
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
ModificadaAlta (7.5)0.94%—Hotels Server Project Hotels Server8/2/201917/6/2026
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
ModificadaCrítica (9.8)1.0%—Hotels Server Project Hotels Server20/1/201917/6/2026
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.