Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.6) | — | — | Progress Software Autonomous Rest Connector Genai AgentsAI | 6/10/2026 | 7/10/2026 | An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user… | |
| Aplazada | Alta (7.5) | 0.32% | — | Museder RestoreoneAI | 6/10/2026 | 6/10/2026 | Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Prestalife Product DesignerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 5/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24. | |
| Aplazada | Media (6.5) | 0.16% | — | Brainstormforce Presto PlayerAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2. | |
| Aplazada | Alta (7.5) | 0.29% | — | Rest API LOGAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | |
| Aplazada | Alta (7.1) | 0.16% | — | Five Star Restaurant ReviewsAI | 1/10/2026 | 1/10/2026 | The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in… | |
| Aplazada | Alta (8.7) | 0.44% | — | RestbedAI | 30/9/2026 | 1/10/2026 | restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through… | |
| Aplazada | Alta (8.7) | 0.55% | — | RestbedAI | 30/9/2026 | 30/9/2026 | restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory… | |
| Aplazada | Baja (2.1) | 0.37% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.33% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 2/10/2026 | A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The… | |
| Aplazada | Alta (8.8) | 0.28% | — | Wpeverest ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim… | |
| Aplazada | Alta (7.2) | 0.24% | — | Restaurant Menu AND Food OrderingAI | 25/9/2026 | 25/9/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | PleskAIPlesk Restful APIAI | 23/9/2026 | 24/9/2026 | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7. | |
| Aplazada | Baja (2.1) | 0.24% | — | Adithyayelloju Restaurant Management SystemAI | 22/9/2026 | 23/9/2026 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search Form. This manipulation of the argument s1 causes sql injection. The attack can be… | |
| Aplazada | Media (5.3) | 0.32% | — | Magnigenie RestropressAI | 21/9/2026 | 21/9/2026 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero. | |
| Aplazada | Baja (2.1) | 0.32% | — | Adithyayelloju Restaurant Management SystemAI | 20/9/2026 | 22/9/2026 | A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/members/price results in sql injection. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Adithyayelloju Restaurant-management-systemAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Redhat ResteasyAI | 18/9/2026 | 18/9/2026 | A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation,… | |
| Pendiente de análisis | Alta (7.4) | 0.23% | — | Redhat ResteasyAI | 18/9/2026 | 5/10/2026 | A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed… | |
| Aplazada | Media (6.5) | 0.27% | — | Magnigenie RestropressAI | 18/9/2026 | 18/9/2026 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. |