Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

314 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.7%—Sourcecodester Restaurant Management System24/10/201917/6/2026
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.
ModificadaMedia (6.1)0.67%—Restaurant Management System Project Restaurant Management System24/10/201917/6/2026
Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
ModificadaMedia (6.1)0.67%—Restaurant Management System Project Restaurant Management System24/10/201917/6/2026
Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
ModificadaAlta (8.8)0.48%—Sourcecodester Restaurant Management System24/10/201917/6/2026
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page.
ModificadaMedia (6.1)0.93%—Easy PDF Restaurant Menu Upload Project Easy PDF Restaurant Menu Upload30/8/201917/6/2026
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
ModificadaCrítica (9.8)3.2%—Restaurant Reservations Project Restaurant Reservations30/8/201917/6/2026
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
ModificadaMedia (6.1)1.1%—Avaya Aura Conferencing31/7/201917/6/2026
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.
ModificadaAlta (7.5)2.2%—Avaya Aura Communication Manager1/2/201917/6/2026
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
ModificadaMedia (5.5)0.53%—Asus Aura Sync Firmware26/12/201817/6/2026
The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.
ModificadaAlta (7.8)0.57%—Asus Aura Sync Firmware26/12/201817/6/2026
The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
ModificadaAlta (7.8)0.57%—Asus Aura Sync Firmware26/12/201817/6/2026
The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
ModificadaCrítica (9.8)3.3%—Avaya Aura System Platform17/10/201817/6/2026
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
ModificadaMedia (6.7)0.30%—Avaya Aura Communication Manager27/9/201817/6/2026
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
ModificadaMedia (6.1)0.77%—Avaya Aura Orchestration Designer21/9/201817/6/2026
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
ModificadaAlta (8.8)0.47%—Auracms2/9/201817/6/2026
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
ModificadaMedia (5.4)0.64%—Auracms8/8/201817/6/2026
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
ModificadaAlta (7.5)1.1%—Auroradao Aura9/5/201817/6/2026
The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack.
ModificadaAlta (7.5)1.2%—Avaya Aura5/2/201817/6/2026
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896.
ModificadaCrítica (9.8)3.0%💥 ExploitHotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script13/12/201717/6/2026
Food Order Script 1.0 has SQL Injection via the /list city parameter.
ModificadaAlta (7.2)4.4%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
ModificadaAlta (7.8)0.56%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
ModificadaMedia (5.9)0.75%—Shidax Restaurant Karaoke25/7/201717/6/2026
The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.
ModificadaAlta (7.5)7.4%💥 ExploitEasycom-aura SQL Iplug15/3/201717/6/2026
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.
ModificadaCrítica (9.8)12%💥 ExploitEasycom-aura Easycom FOR PHP15/3/201717/6/2026
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.
ModificadaAlta (7.5)1.3%—Restaurantbiller Restaurant Biller2/2/201517/6/2026
SQL injection vulnerability in Restaurant Biller allows remote attackers to execute arbitrary SQL commands via the cid parameter in a category action to index.php.