Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.61%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability has been found in Campcodes Coffee Shop POS System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/categories/view_category.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has…
ModificadaAlta (7.5)0.61%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability, which was classified as critical, was found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/sales/view_details.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
ModificadaMedia (5.4)0.70%—Haml-coffee Project Haml-coffee14/5/202117/6/2026
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its configuration options. A vulnerable application that passes user…
ModificadaMedia (6.5)1.1%—Smarter Coffee Maker 1ST Generation7/10/202017/6/2026
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.5)0.93%—Coffeecoin Project Coffeecoin3/7/201817/6/2026
The mintToken function of a smart contract implementation for Coffeecoin (COFFEE), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (8.1)0.55%—Ipip-coffee4/6/201817/6/2026
ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integrity and availability of the data being used to make geolocation decisions by an application.
ModificadaMedia (5.5)0.37%—Tcoffee T-coffee7/8/201717/6/2026
t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally.
ModificadaMedia (5.4)0.27%—Coffee-inn Coffee INN16/10/201417/6/2026
The Coffee Inn (aka lt.lemonlabs.android.coffeeinn) application 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)3.7%—Adazing Morning Coffee28/9/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
ModificadaAlta (10)4.6%—Juracapecoffee Internet Connectivity KIT8/9/200916/6/2026
Multiple buffer overflows in the Jura Internet Connection Kit for the Jura Impressa F90 coffee maker allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to improper use of the gets and sprintf functions.
ModificadaAlta (10)4.7%—Juracapecoffee Internet Connectivity KIT8/9/200916/6/2026
The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged functions, which allows remote attackers to cause a denial of service (physical damage), modify coffee settings, and possibly execute code via a crafted request. NOTE: this issue is being included in…
ModificadaMedia (5)1.3%—Coffeecup Software Coffeecup Password Wizard31/12/200316/6/2026
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
ModificadaMedia (4.6)0.21%—Coffeecup Software Coffeecup Direct FTPCoffeecup Software Coffeecup Free FTP12/2/200116/6/2026
CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.