Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.26%—Easy Restaurant Menu ManagerAI4/7/202517/6/2026
The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_eprm_menu_link shortcode in versions up to, and including 2.0.1, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.6)1.3%—Restdb Codehooks IO MCP ServerAI1/7/202517/6/2026
RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server is written in a way that is vulnerable to command injection attacks as part of some of its MCP Server tools definition and implementation. This could result in a user initiated remote command…
AnalizadaAlta (7.5)0.68%—Wpeverest Everest Forms25/6/202517/6/2026
The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily…
AplazadaMedia (5.1)0.22%—Purestorage FlasharrayAI16/6/202517/6/2026
A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.
AnalizadaMedia (5.5)0.49%—Carmelogarcia Restaurant Order System16/6/202517/6/2026
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (5.5)0.48%—Carmelogarcia Restaurant Order System16/6/202517/6/2026
A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerability affects unknown code of the file /payment.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…
AnalizadaBaja (2.1)0.43%—Fabian Restaurant Order System16/6/202517/6/2026
A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AplazadaMedia (6.5)0.62%—Restrict File AccessAI14/6/202517/6/2026
The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain…
AplazadaCrítica (9.8)0.63%💥 PoCRest API Custom API Generator FOR Cross Platform AND Import Export IN WPAI13/6/202517/6/2026
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated attackers to POST an arbitrary import_api…
AplazadaMedia (5.4)0.26%—Euroinformation MoneticopaiementAIPrestashopAI12/6/202517/6/2026
Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or callback.php.
AnalizadaMedia (5.5)0.51%—Carmelogarcia Restaurant Order System10/6/202517/6/2026
A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaBaja (2)0.30%—Phpgurukul Restaurant Table Booking System10/6/202517/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this issue is some unknown functionality of the file /check-status.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The…
AnalizadaBaja (1.9)0.30%—Phpgurukul Restaurant Table Booking System10/6/202517/6/2026
A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-table.php. The manipulation of the argument tableno leads to cross site scripting. The attack can be launched remotely. The exploit…
AnalizadaBaja (1.9)0.30%—Phpgurukul Restaurant Table Booking System10/6/202517/6/2026
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/manage-subadmins.php. The manipulation of the argument fullname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
AplazadaAlta (8.3)0.33%—Purestorage FlashbladeAI10/6/202517/6/2026
Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.
AplazadaAlta (8.7)0.38%—Purestorage FlasharrayAI10/6/202517/6/2026
Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.
AnalizadaBaja (1.9)0.30%—Phpgurukul Restaurant Table Booking System10/6/202517/6/2026
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit…
AplazadaMedia (4.3)0.16%—Everestthemes Everest BackupAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request Forgery.This issue affects Everest Backup: from n/a through <= 2.3.3.
AplazadaMedia (5.9)0.26%—Marvie Pons Pinterest Verify Meta TAGAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marvie Pons Pinterest Verify Meta Tag pinterest-verify-meta-tag allows Stored XSS.This issue affects Pinterest Verify Meta Tag: from n/a through <= 1.3.
AnalizadaMedia (6.5)0.22%—Pluginsandsnippets Simple Page Access Restriction30/5/202517/6/2026
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers…
AplazadaMedia (6.6)0.61%—Laravel Rest APIAI30/5/202517/6/2026
Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, and update actions),…
AnalizadaCrítica (9.8)0.34%—Forestryks Process-sync24/5/202517/6/2026
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
ModificadaCrítica (9.8)0.48%—Phpgurukul Restaurant Table Booking System23/5/202517/6/2026
PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.
AplazadaAlta (7.1)0.22%—Catkin Redi-restaurant-reservationAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation redi-restaurant-reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through <= 24.1209.
ModificadaAlta (8.2)0.31%—Themegoods Grand Restaurant19/5/202517/6/2026
Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0.
Orbitaley — Vulnerabilidades