Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.56%—Sfturing Hosp OrderAI7/9/202628/9/2026
A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in…
AplazadaMedia (5.5)0.56%—Sfturing Hosp OrderAI7/9/202628/9/2026
A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument…
AplazadaMedia (5.5)0.56%—Sfturing Hosp OrderAI7/9/202628/9/2026
A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to…
AplazadaMedia (5.5)0.60%—Sfturing Hosp OrderAI7/9/202628/9/2026
A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery. Performing a manipulation results in unverified…
AplazadaMedia (5.3)0.16%—Restaurant Menu AND Food OrderingAI4/9/20268/9/2026
The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment.
AplazadaMedia (6.5)0.29%—Flycart Pre-orders FOR WoocommerceAI3/9/20263/9/2026
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
AplazadaAlta (7.1)0.25%—Upsell Order Bump Offer FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI26/8/202629/8/2026
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaAlta (8.7)0.45%—Order TIPAI26/8/202626/8/2026
The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.
AplazadaMedia (5.5)0.41%—Sililawijesinghe Food Ordering SystemAI25/8/202628/8/2026
A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote exploitation of the attack is possible.…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI24/8/202624/8/2026
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI24/8/202626/8/2026
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI24/8/202624/8/2026
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI24/8/202627/8/2026
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI24/8/202624/8/2026
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI20/8/202624/8/2026
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has…
AplazadaBaja (2.1)0.33%—Sourcecodester Simple Online Food Ordering SystemAI20/8/202624/8/2026
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI20/8/202625/8/2026
A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may…
AplazadaBaja (2)0.40%—Sourcecodester Simple Online Food Ordering SystemAI20/8/202624/8/2026
A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI19/8/202620/8/2026
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI19/8/202621/8/2026
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Online Food Ordering SystemAI19/8/202621/8/2026
A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and…
AnalizadaAlta (7.2)0.14%—Oracle Order Management18/8/202628/8/2026
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to…
AnalizadaAlta (7.5)0.33%—Oracle Order Management18/8/202628/8/2026
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.…
AnalizadaAlta (7.1)0.24%—Oracle Order Management18/8/202628/8/2026
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the…