Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.54% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. The manipulation of the argument username/mobileno leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.1) | 0.41% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.60% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.57% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /add-table.php. The manipulation of the argument tableno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.57% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.39% | — | Socialevolution WP Find Your NearestAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Reflected XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Analizada | Media (6.1) | 0.32% | — | Wpeverest User Registration | 28/2/2025 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.82% | — | Quarkus-resteasyAI | 26/2/2025 | 17/6/2026 | A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError. | |
| Analizada | Crítica (9.8) | 29% | — | Wpeverest Everest Forms | 25/2/2025 | 17/6/2026 | The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including,… | |
| Modificada | Media (6.5) | 0.43% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters. | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Analizada | Alta (8.8) | 0.61% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter. | |
| Aplazada | Media (5.3) | 0.63% | — | Octokit Plugin-paginate-restAI | 14/2/2025 | 17/6/2026 | @octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link`… | |
| Aplazada | Alta (8.3) | 0.82% | — | Quarkusio Quarkus RestAI | 13/2/2025 | 4/8/2026 | A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information. | |
| Analizada | Baja (3.5) | 0.34% | — | Wpeverest Everest Forms | 13/2/2025 | 17/6/2026 | The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (4.8) | 0.27% | — | PrestashopAI | 12/2/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie… | |
| Analizada | Media (5.3) | 0.38% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file select-menu.php. The manipulation of the argument table leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.52% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/approve-reject.php. The manipulation of the argument breject_id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (4.8) | 0.28% | — | Forestblog Project Forestblog | 3/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function. | |
| Analizada | Media (5.4) | 0.22% | — | Wordpresteem WE - Testimonial Slide | 30/1/2025 | 17/6/2026 | The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Names in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.33% | — | Alex Reservations Smart Restaurant BookingAI | 30/1/2025 | 17/6/2026 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.20% | — | Kube-audit-restAI | 29/1/2025 | 17/6/2026 | kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16. | |
| Analizada | Alta (7.5) | 0.46% | — | Liquidweb Restrict Content | 26/1/2025 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to… |