Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.50% | — | Wpeverest Everest Forms Frontend Listing | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Forms - Frontend Listing: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.4) | 0.19% | — | WP Restaurant ListingsAI | 22/10/2025 | 17/6/2026 | The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter of the restaurant_summary shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.1) | 0.25% | — | Hockeycomputindo Bang Resto | 21/10/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly in the browser. When… | |
| Analizada | Media (6.5) | 0.27% | — | Rajvi-patel-22 Restaurant-management-system-dbms-project | 20/10/2025 | 17/6/2026 | There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through specially crafted SQL query strings. | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface. | |
| Analizada | Crítica (9.9) | 0.50% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen. | |
| Analizada | Media (5.8) | 0.51% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders. | |
| Analizada | Media (5.8) | 0.38% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path. | |
| Analizada | Alta (7.7) | 0.54% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers. | |
| Analizada | Crítica (9.9) | 0.72% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation. | |
| Analizada | Alta (7.7) | 0.46% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users. | |
| Analizada | Alta (8.6) | 0.32% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages. | |
| Analizada | Alta (8.6) | 0.49% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account. | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 30/9/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume. | |
| Analizada | Baja (3.8) | 0.27% | — | Prestashop Checkout | 16/10/2025 | 17/6/2026 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist. | |
| Analizada | Media (4.1) | 0.92% | — | Prestashop Checkout | 16/10/2025 | 17/6/2026 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds… | |
| Analizada | Crítica (9.1) | 0.50% | 💥 PoC | Prestashop Checkout | 16/10/2025 | 17/6/2026 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5.… | |
| Aplazada | Media (5.9) | 0.40% | 💥 PoC | Everestthemes Everest BackupAI | 11/10/2025 | 17/6/2026 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 92% | ⚠ Explotación activa💥 Exploit | Gladinet CentrestackGladinet Triofox | 9/10/2025 | 17/6/2026 | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions… | |
| Aplazada | Crítica (9.8) | 2.3% | 💥 Exploit | Magnigenie RestropressAI | 3/10/2025 | 17/6/2026 | The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT… | |
| Aplazada | Media (5.3) | 0.15% | — | Restrict User RegistrationAI | 3/10/2025 | 30/9/2026 | The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the update() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Aplazada | Crítica (9.8) | 0.60% | 💥 PoC | Copypress Rest APIAI | 30/9/2025 | 17/6/2026 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function in versions 1.1 to 1.2. The plugin falls back to a hard-coded JWT signing key when no secret is defined and does not restrict which file types can be fetched and saved as attachments. As a result,… | |
| Analizada | Baja (2.1) | 0.35% | — | Phpjabbers Restaurant Menu Maker | 23/9/2025 | 17/6/2026 | A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (5.9) | 0.22% | — | Will.i.am Simple Restaurant MenuAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will.I.am Simple Restaurant Menu simple-restaurant-menu allows Stored XSS.This issue affects Simple Restaurant Menu: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Codefish Pinterest Pinboard WidgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7. |