Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.56% | — | Code-projects Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/user_save.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.46% | — | Adonesevangelista Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/member_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.46% | — | Adonesevangelista Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.46% | — | Adonesevangelista Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/category_update.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.56% | — | Code-projects Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/category_save.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.56% | — | Code-projects Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menu_update.php. The manipulation of the argument menu leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.9) | 0.60% | — | Code-projects Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.60% | — | Code-projects Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. This issue affects some unknown processing of the file /payment_save.php. The manipulation of the argument mode leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.60% | — | Code-projects Online Restaurant Management System | 7/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. This vulnerability affects unknown code of the file /reservation_save.php. The manipulation of the argument first leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.4) | 0.49% | — | TIM Nguyen 1-click Backup Restore DatabaseAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3. | |
| Analizada | Media (5.1) | 0.47% | — | Phpgurukul Restaurant Table Booking System | 4/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /edit-subadmin.php. The manipulation of the argument fullname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.47% | — | Phpgurukul Restaurant Table Booking System | 4/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Gladinet Centrestack | 3/4/2025 | 17/6/2026 | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to… | |
| Aplazada | Media (4.3) | 0.25% | — | Magnigenie RestropressAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.8. | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component Friend Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.3) | 0.28% | — | Jaap Jansma Connector TO Civicrm With CivimcrestfaceAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Connector to CiviCRM with CiviMcRestFace: from n/a through <= 1.0.10. | |
| Aplazada | Alta (8.2) | 0.40% | — | Streamsoft PrestizAI | 28/3/2025 | 17/6/2026 | Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed. This issue was… | |
| Aplazada | Alta (8.6) | 0.44% | — | Streamsoft PrestizAI | 28/3/2025 | 17/6/2026 | Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker. This issue was fixed in 18.1.376.37 version of the software. | |
| Aplazada | Media (6.5) | 0.22% | — | Graham Quick Interest SliderAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Interest Slider quick-interest-slider allows DOM-Based XSS.This issue affects Quick Interest Slider: from n/a through <= 3.1.5. | |
| Modificada | Media (4.8) | 0.31% | — | Wpeverest User Registration & Membership | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Stored XSS.This issue affects User Registration: from n/a through <= 4.0.3. | |
| Aplazada | Media (4.9) | 0.62% | — | Rustaurius Five Star Restaurant ReservationsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29. | |
| Aplazada | Alta (8.8) | 0.75% | — | Motopress Mp-restaurant-menuAIPHPAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows PHP Local File Inclusion.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.4. | |
| Aplazada | Alta (8.8) | 0.22% | — | Foodbakery Delivery Restaurant DirectoryAI | 19/3/2025 | 17/6/2026 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save,… | |
| Aplazada | Media (4.3) | 0.17% | — | Rest API TO MiniprogramAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram rest-api-to-miniprogram allows Cross Site Request Forgery.This issue affects REST API TO MiniProgram: from n/a through <= 5.1.2. |