Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

314 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.48%—Restaurant ZoneAI17/6/202617/6/2026
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
AplazadaAlta (7.5)0.43%—Fivestarplugins Five Star Restaurant ReservationsAI2/6/202622/7/2026
Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.
AplazadaMedia (5.3)0.24%—Fivestarplugins Five Star Restaurant ReservationsAI30/4/202617/6/2026
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's…
AnalizadaMedia (6.6)0.19%—Saurabh-kumar Python-dotenv20/4/202617/6/2026
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device…
AplazadaMedia (5.4)0.30%—Restaurant CafeteriaAI28/3/202617/6/2026
The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged operations. An attacker can install and activate a from a user-supplied URL, leading to arbitrary PHP code execution, and…
AnalizadaAlta (8.8)0.47%—Wecodex Restaurant CMS26/3/202617/6/2026
Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind…
AplazadaMedia (6.5)0.21%—Rustaurius Five Star Restaurant ReservationsAI25/3/202617/6/2026
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9.
AplazadaAlta (7.1)0.23%—E4jvikwp VikrestaurantsAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5.2.
AplazadaMedia (5.3)0.29%—Rarathemes Restaurant AND CafeAI13/3/202617/6/2026
Missing Authorization vulnerability in raratheme Restaurant and Cafe restaurant-and-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant and Cafe: from n/a through <= 1.2.5.
AplazadaCrítica (9.8)0.40%—Themegoods Grand RestaurantAI19/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.
AplazadaMedia (4.3)0.15%—Fivestarplugins Five Star Restaurant ReservationsAI2/2/202617/6/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.
AplazadaMedia (5.3)0.30%—Thingsforrestaurants Quick Restaurant ReservationsAI23/1/202617/6/2026
Missing Authorization vulnerability in Alejandro Quick Restaurant Reservations quick-restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Restaurant Reservations: from n/a through <= 1.6.7.
AplazadaMedia (6.5)0.27%—Themegoods Grand Restaurant Theme Elements FOR ElementorAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1.
AplazadaAlta (7.1)0.30%—Ayecode RestauranteAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ayecode Restaurante restaurante allows Reflected XSS.This issue affects Restaurante: from n/a through <= 3.0.7.
ModificadaAlta (7.1)0.22%—Themegoods Grand Restaurant8/1/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9.
AplazadaMedia (6.4)0.33%—Snillrik RestaurantAI7/1/202617/6/2026
The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…
AplazadaAlta (8.6)0.27%—Rustaurius Five Star Restaurant ReservationsAI5/1/20267/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4.
AplazadaMedia (5.4)0.12%—Rustaurius Five Star Restaurant ReservationsAI24/12/20257/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8.
AplazadaMedia (6.1)0.21%—Fivestarplugins Five Star Restaurant ReservationsAI21/12/202517/6/2026
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaMedia (6.5)0.34%—Motopress Mp-restaurant-menuAI18/12/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7.
AnalizadaAlta (7.5)0.24%💥 PoCAbacre Restaurant Point OF Sale3/12/202517/6/2026
Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory during an activation attempt.
AplazadaBaja (2.1)0.32%—Jairiidriss RestaurantwebsiteAI1/12/20253/9/2026
A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the argument selected_date causes cross site scripting. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (6.5)0.24%—Hackerwhale Restaurant Website Restoran19/11/202517/6/2026
Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.
AplazadaAlta (7.2)0.64%💥 PoCAlex Reservations Smart Restaurant BookingAI8/11/202517/6/2026
The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level…
AplazadaMedia (6.5)0.32%—Gaurav Aggarwal Backup AND MoveAI6/11/202517/6/2026
Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup and Move: from n/a through <= 0.1.
Orbitaley — Vulnerabilidades