Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.33% | — | E4jvikwp VikrestaurantsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Stored XSS.This issue affects VikRestaurants: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.1) | 0.34% | — | E4jvikwp VikrestaurantsAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5. | |
| Aplazada | Crítica (9.8) | 0.24% | — | Bedevious Password Reset With Code FOR Wordpress Rest APIAI | 18/9/2025 | 17/6/2026 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
| Aplazada | Baja (3.1) | 0.24% | — | Everest LibocppAI | 15/9/2025 | 17/6/2026 | The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created with StringTooLarge set to Throw. | |
| Aplazada | Media (6.8) | 0.46% | — | Crestron Touchscreens X70AI | 9/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061… | |
| Aplazada | Media (5.9) | 0.37% | — | Crestron Tsw-760AICrestron Tsw-1060AI | 9/9/2025 | 17/6/2026 | A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the… | |
| Aplazada | Crítica (9.3) | 0.36% | — | PrestAI | 8/9/2025 | 17/6/2026 | pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible in versions prior to 2.0.0-rc3. The validation present in versions prior to 2.0.0-rc3 does not provide adequate protection from injection attempts. Version 2.0.0-rc3 contains a patch to mitigate… | |
| Analizada | Baja (3.7) | 0.82% | 💥 Exploit | Prestashop | 8/9/2025 | 17/6/2026 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature. | |
| Aplazada | Crítica (9.8) | 0.49% | 💥 PoC | Scriptsbundle AdforestAI | 6/9/2025 | 1/10/2026 | The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators,… | |
| Aplazada | Media (6.5) | 0.21% | — | Best Restaurant Menu BY PricelistoAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto allows Stored XSS.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.3. | |
| Aplazada | Alta (8.6) | 0.37% | — | Crestron Touchscreens X70AICrestron Tsw-x70AICrestron Tsw-x60AICrestron Tst-1080AI+9 | 3/9/2025 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid… | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32. | |
| Aplazada | Media (4.3) | 0.13% | — | Restore Permanently Delete Post OR Page DataAI | 23/8/2025 | 17/6/2026 | The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the rp_dpo_dpa_ajax_dp_delete_data() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.56% | — | Acato WP Rest CacheAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acato WP REST Cache wp-rest-cache allows PHP Local File Inclusion.This issue affects WP REST Cache: from n/a through <= 2025.1.0. | |
| Aplazada | Alta (8.5) | 0.28% | — | Valvepress Pinterest Automatic PINAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows SQL Injection.This issue affects Pinterest Automatic Pin: from n/a through < 4.19.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Easy Restaurant Menu ManagerAI | 13/8/2025 | 17/6/2026 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the nsc_eprm_save_menu() function. This makes it possible for unauthenticated attackers to upload a menu file via a… | |
| Aplazada | Media (4.3) | 0.15% | — | CBX Restaurant BookingAI | 11/8/2025 | 17/6/2026 | The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Alta (7.8) | 0.24% | — | Carmelogarcia Restaurant Order System | 1/8/2025 | 5/7/2026 | SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file | |
| Modificada | Media (6.5) | 0.63% | — | Prestashop | 30/7/2025 | 5/7/2026 | A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. | |
| Modificada | Media (6.5) | 0.80% | — | Prestashop | 30/7/2025 | 5/7/2026 | A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request. | |
| Aplazada | Media (6.4) | 0.32% | — | Wpeverest User RegistrationAI | 22/7/2025 | 17/6/2026 | The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.14% | — | Motopress Mp-restaurant-menuAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6. | |
| Analizada | Media (6.1) | 0.14% | — | Oracle Rest Data Services | 15/7/2025 | 17/6/2026 | Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks require human interaction from a person other than… | |
| Aplazada | Alta (8.1) | 0.29% | — | Restrict File AccessAI | 15/7/2025 | 17/6/2026 | The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the… | |
| Aplazada | Crítica (9.8) | 0.59% | 💥 PoC | Premium AGE Verification RestrictionAI | 11/7/2025 | 17/6/2026 | The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated… |