Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
314 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.7% | — | Sourcecodester Restaurant Management System | 24/10/2019 | 17/6/2026 | Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files. | |
| Modificada | Media (6.1) | 0.67% | — | Restaurant Management System Project Restaurant Management System | 24/10/2019 | 17/6/2026 | Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member. | |
| Modificada | Media (6.1) | 0.67% | — | Restaurant Management System Project Restaurant Management System | 24/10/2019 | 17/6/2026 | Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen. | |
| Modificada | Alta (8.8) | 0.48% | — | Sourcecodester Restaurant Management System | 24/10/2019 | 17/6/2026 | Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page. | |
| Modificada | Media (6.1) | 0.93% | — | Easy PDF Restaurant Menu Upload Project Easy PDF Restaurant Menu Upload | 30/8/2019 | 17/6/2026 | The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 3.2% | — | Restaurant Reservations Project Restaurant Reservations | 30/8/2019 | 17/6/2026 | The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. | |
| Modificada | Media (6.1) | 1.1% | — | Avaya Aura Conferencing | 31/7/2019 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated. | |
| Modificada | Alta (7.5) | 2.2% | — | Avaya Aura Communication Manager | 1/2/2019 | 17/6/2026 | A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1. | |
| Modificada | Media (5.5) | 0.53% | — | Asus Aura Sync Firmware | 26/12/2018 | 17/6/2026 | The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address. | |
| Modificada | Alta (7.8) | 0.57% | — | Asus Aura Sync Firmware | 26/12/2018 | 17/6/2026 | The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.57% | — | Asus Aura Sync Firmware | 26/12/2018 | 17/6/2026 | The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code. | |
| Modificada | Crítica (9.8) | 3.3% | — | Avaya Aura System Platform | 17/10/2018 | 17/6/2026 | A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2. | |
| Modificada | Media (6.7) | 0.30% | — | Avaya Aura Communication Manager | 27/9/2018 | 17/6/2026 | A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1. | |
| Modificada | Media (6.1) | 0.77% | — | Avaya Aura Orchestration Designer | 21/9/2018 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1. | |
| Modificada | Alta (8.8) | 0.47% | — | Auracms | 2/9/2018 | 17/6/2026 | An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic. | |
| Modificada | Media (5.4) | 0.64% | — | Auracms | 8/8/2018 | 17/6/2026 | AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action. | |
| Modificada | Alta (7.5) | 1.1% | — | Auroradao Aura | 9/5/2018 | 17/6/2026 | The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack. | |
| Modificada | Alta (7.5) | 1.2% | — | Avaya Aura | 5/2/2018 | 17/6/2026 | System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Hotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script | 13/12/2017 | 17/6/2026 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Media (5.9) | 0.75% | — | Shidax Restaurant Karaoke | 25/7/2017 | 17/6/2026 | The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Easycom-aura SQL Iplug | 15/3/2017 | 17/6/2026 | EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Easycom-aura Easycom FOR PHP | 15/3/2017 | 17/6/2026 | Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function. | |
| Modificada | Alta (7.5) | 1.3% | — | Restaurantbiller Restaurant Biller | 2/2/2015 | 17/6/2026 | SQL injection vulnerability in Restaurant Biller allows remote attackers to execute arbitrary SQL commands via the cid parameter in a category action to index.php. |