Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability has been found in Campcodes Coffee Shop POS System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/categories/view_category.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/sales/view_details.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.70% | — | Haml-coffee Project Haml-coffee | 14/5/2021 | 17/6/2026 | haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its configuration options. A vulnerable application that passes user… | |
| Modificada | Media (6.5) | 1.1% | — | Smarter Coffee Maker 1ST Generation | 7/10/2020 | 17/6/2026 | Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 0.93% | — | Coffeecoin Project Coffeecoin | 3/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Coffeecoin (COFFEE), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.1) | 0.55% | — | Ipip-coffee | 4/6/2018 | 17/6/2026 | ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integrity and availability of the data being used to make geolocation decisions by an application. | |
| Modificada | Media (5.5) | 0.37% | — | Tcoffee T-coffee | 7/8/2017 | 17/6/2026 | t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally. | |
| Modificada | Media (5.4) | 0.27% | — | Coffee-inn Coffee INN | 16/10/2014 | 17/6/2026 | The Coffee Inn (aka lt.lemonlabs.android.coffeeinn) application 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.7% | — | Adazing Morning Coffee | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | |
| Modificada | Alta (10) | 4.6% | — | Juracapecoffee Internet Connectivity KIT | 8/9/2009 | 16/6/2026 | Multiple buffer overflows in the Jura Internet Connection Kit for the Jura Impressa F90 coffee maker allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to improper use of the gets and sprintf functions. | |
| Modificada | Alta (10) | 4.7% | — | Juracapecoffee Internet Connectivity KIT | 8/9/2009 | 16/6/2026 | The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged functions, which allows remote attackers to cause a denial of service (physical damage), modify coffee settings, and possibly execute code via a crafted request. NOTE: this issue is being included in… | |
| Modificada | Media (5) | 1.3% | — | Coffeecup Software Coffeecup Password Wizard | 31/12/2003 | 16/6/2026 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. | |
| Modificada | Media (4.6) | 0.21% | — | Coffeecup Software Coffeecup Direct FTPCoffeecup Software Coffeecup Free FTP | 12/2/2001 | 16/6/2026 | CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords. |