Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.96%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu.
ModificadaCrítica (9.1)1.2%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.
ModificadaCrítica (9.8)1.1%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
ModificadaMedia (4.8)0.60%—Fast Food Ordering System Project Fast Food Ordering System7/6/202217/6/2026
A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.php of the Master List. The manipulation of the argument Description with the input foo "><img src="" onerror="alert(document.cookie)"> leads to cross site scripting. It is possible to launch the…
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
ModificadaAlta (7.2)1.0%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
ModificadaAlta (7.2)1.0%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
ModificadaAlta (7.2)1.0%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
ModificadaAlta (7.2)0.86%—Online Ordering System Project Online Ordering System2/6/202217/6/2026
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
ModificadaAlta (7.2)1.5%—Oretnom23 Online Food Ordering System25/5/202217/6/2026
An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaCrítica (9.8)1.3%—Oretnom23 Online Food Ordering System25/5/202217/6/2026
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.
ModificadaMedia (5.4)0.58%—Gadget Works Online Ordering System Project Gadget Works Online Ordering System28/1/202217/6/2026
A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.
ModificadaCrítica (9.8)2.5%💥 PoCOretnom23 Online Food Ordering System29/10/202117/6/2026
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
ModificadaCrítica (9.8)1.9%—Responsive Ordering System Project Responsive Ordering System23/7/202117/6/2026
Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php.
ModificadaCrítica (9.8)1.9%—Online Ordering System Project Online Ordering System22/7/202117/6/2026
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
ModificadaAlta (7.5)16%—Online Ordering System Project Online Ordering System16/3/202117/6/2026
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
ModificadaCrítica (9.8)3.7%—Online Ordering System Project Online Ordering System16/3/202117/6/2026
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
ModificadaMedia (4.8)0.71%—Bakeshop Online Ordering System Project Bakeshop Online Ordering System26/1/202117/6/2026
Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories".
Orbitaley — Vulnerabilidades