Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
314 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 15/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php. | |
| Modificada | Media (5.4) | 0.61% | — | Fivestarplugins Five Star Restaurant Reservations | 24/1/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting… | |
| Modificada | Media (5.4) | 0.62% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 20/1/2022 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters. | |
| Modificada | Media (4.8) | 0.64% | — | Motopress Restaurant Menu | 1/11/2021 | 17/6/2026 | The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.8) | 0.78% | — | Avaya Aura Device Services | 25/6/2021 | 17/6/2026 | An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services. | |
| Modificada | Media (5.4) | 0.34% | — | Avaya Aura Experience Portal | 24/6/2021 | 17/6/2026 | Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix). | |
| Modificada | Media (6.1) | 0.38% | — | Avaya Aura Experience Portal | 24/6/2021 | 17/6/2026 | A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix). | |
| Modificada | Alta (7.8) | 0.64% | — | Avaya Aura Appliance Virtualization Platform | 24/6/2021 | 17/6/2026 | A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU. | |
| Modificada | Media (5.5) | 0.70% | — | Avaya Aura Appliance Virtualization Platform | 24/6/2021 | 17/6/2026 | An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a… | |
| Modificada | Alta (7.8) | 0.48% | — | Avaya Aura Utility Services | 24/6/2021 | 17/6/2026 | A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services | |
| Modificada | Alta (8.8) | 0.51% | — | Avaya Aura Utility Services | 24/6/2021 | 17/6/2026 | A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services | |
| Modificada | Media (5.5) | 0.62% | — | Avaya Aura Utility Services | 24/6/2021 | 17/6/2026 | An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects all 7.x versions… | |
| Modificada | Media (6.1) | 5.5% | 💥 Exploit | Catzsoft Redi Restaurant Reservation | 17/5/2021 | 17/6/2026 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to… | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Void Aurall REC Monitor | 23/4/2021 | 17/6/2026 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1. | |
| Modificada | Alta (7.5) | 0.87% | — | Void Aural REC Monitor | 23/4/2021 | 17/6/2026 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server. | |
| Modificada | Media (6.5) | 1.1% | — | Avaya Aura Orchestration Designer | 23/4/2021 | 17/6/2026 | An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3. | |
| Modificada | Crítica (9.8) | 31% | — | Fivestarplugins Five Star Restaurant Menu | 11/3/2021 | 17/6/2026 | The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php. | |
| Modificada | Alta (8.8) | 1.6% | — | Restaurant Reservation System Project Restaurant Reservation System | 7/1/2021 | 17/6/2026 | Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php. | |
| Modificada | Crítica (9.8) | 6.1% | — | Multi Restaurant Table Reservation System Project Multi Restaurant Table Reservation System | 2/12/2020 | 17/6/2026 | The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Karenderia Multiple Restaurant System Project Karenderia Multiple Restaurant System | 24/11/2020 | 17/6/2026 | A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database. | |
| Modificada | Media (6.5) | 2.9% | — | Avaya Aura System ManagerAvaya Weblm | 13/11/2020 | 17/6/2026 | An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2. | |
| Modificada | Alta (8.8) | 0.43% | — | Avaya Aura Communication ManagerAvaya Aura Messaging | 11/8/2020 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the… | |
| Modificada | Alta (7.8) | 0.73% | — | Asus Aura Sync | 2/6/2020 | 17/6/2026 | Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption. | |
| Modificada | Alta (8.6) | 1.7% | — | Avaya Aura Conferencing | 28/2/2020 | 17/6/2026 | A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server. | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. |