Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.46% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Crítica (9.8) | 0.55% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Path Traversal.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Media (5.3) | 0.26% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Media (4.3) | 0.14% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request Forgery.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Analizada | Media (6.9) | 0.51% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/assign_save.php. The manipulation of the argument team leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.54% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_update.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.54% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user_save.php. The manipulation of the argument username/name leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.54% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.51% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Restaurant Management System 1.0. This affects an unknown part of the file /admin/member_update.php. The manipulation of the argument menu leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.54% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.54% | — | Adonesevangelista Restaurant Management System | 18/5/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/finished.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (4.3) | 0.28% | — | Valvepress Pinterest Automatic PINAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinterest Automatic Pin: from n/a through <= 4.19.0. | |
| Analizada | Media (4.8) | 0.35% | — | Wpeverest Everest Forms | 15/5/2025 | 17/6/2026 | The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (8.8) | 0.19% | — | Restrict Route BY IP Project Restrict Route BY IP | 14/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0. | |
| Analizada | Media (6.1) | 0.28% | — | Wpeverest Everest Forms | 12/5/2025 | 17/6/2026 | Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload. | |
| Aplazada | Crítica (9.8) | 0.87% | — | Grocery-cms-php-restful-apiAI | 8/5/2025 | 17/6/2026 | Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php. | |
| Aplazada | Alta (8.7) | 0.38% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Crítica (10) | 0.29% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Media (5.3) | 0.43% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Media (5.1) | 0.44% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Images in Crestron Automate VX is active, snapshots of the captured video or portions thereof are stored locally on the system, and there is no visible indication that this is… | |
| Analizada | Media (6.9) | 0.60% | — | Adonesevangelista Restaurant Management System | 2/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/category_update.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.60% | — | Adonesevangelista Restaurant Management System | 2/5/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/category_save.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.29% | — | Wpeverest User Registration & Membership | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through < 4.2.0. | |
| Aplazada | Alta (7.5) | 0.75% | — | Everestthemes Grace MAGAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in everestthemes Grace Mag grace-mag allows PHP Local File Inclusion.This issue affects Grace Mag: from n/a through <= 1.1.5. | |
| Aplazada | Media (6.4) | 0.32% | — | Cuba Rest API Add-onAI | 22/4/2025 | 17/6/2026 | The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the… |