Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
295 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Online Ordering System Project Online Ordering System | 2/6/2022 | 17/6/2026 | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. | |
| Modificada | Alta (7.2) | 1.0% | — | Online Ordering System Project Online Ordering System | 2/6/2022 | 17/6/2026 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | |
| Modificada | Alta (7.2) | 0.86% | — | Online Ordering System Project Online Ordering System | 2/6/2022 | 17/6/2026 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | |
| Modificada | Alta (7.2) | 1.5% | — | Oretnom23 Online Food Ordering System | 25/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Crítica (9.8) | 1.3% | — | Oretnom23 Online Food Ordering System | 25/5/2022 | 17/6/2026 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php. | |
| Modificada | Media (5.4) | 0.58% | — | Gadget Works Online Ordering System Project Gadget Works Online Ordering System | 28/1/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php. | |
| Modificada | Crítica (9.8) | 2.5% | 💥 PoC | Oretnom23 Online Food Ordering System | 29/10/2021 | 17/6/2026 | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters. | |
| Modificada | Crítica (9.1) | 2.0% | 💥 PoC | Online Food Ordering WEB APP Project Online Food Ordering WEB APP | 1/10/2021 | 17/6/2026 | An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user. | |
| Modificada | Crítica (9.8) | 1.9% | — | Responsive Ordering System Project Responsive Ordering System | 23/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Online Ordering System Project Online Ordering System | 22/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php. | |
| Modificada | Alta (7.5) | 16% | — | Online Ordering System Project Online Ordering System | 16/3/2021 | 17/6/2026 | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | |
| Modificada | Crítica (9.8) | 3.7% | — | Online Ordering System Project Online Ordering System | 16/3/2021 | 17/6/2026 | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). | |
| Modificada | Media (4.8) | 0.71% | — | Bakeshop Online Ordering System Project Bakeshop Online Ordering System | 26/1/2021 | 17/6/2026 | Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories". | |
| Modificada | Alta (8) | 0.55% | — | Phpscriptsmall Online Food Ordering Script | 23/2/2019 | 17/6/2026 | PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Bsen Ordering Software Project Bsen Ordering Software | 16/11/2018 | 17/6/2026 | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. | |
| Modificada | Media (5.4) | 0.27% | — | Orderingapps Buckhorn Grill | 4/10/2014 | 17/6/2026 | The Buckhorn Grill (aka com.orderingapps.buckhorn) application 2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Orderingapps Sweatshop | 30/9/2014 | 17/6/2026 | The Sweatshop (aka com.orderingapps.sweatshop) application 2.96 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (2.1) | 0.56% | — | Zippyyum Subway Ordering FOR California | 12/12/2013 | 17/6/2026 | The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Digitizing Quote AND Ordering System | 9/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter. | |
| Modificada | Media (6) | 0.94% | 💥 Exploit | Digitizing Quote AND Ordering System | 31/12/2006 | 16/6/2026 | SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter. |