Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—SEO Nutrition AND Print FOR Recipes BY EdamamAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Edamam SEO, Nutrition and Print for Recipes by Edamam seo-nutrition-and-print-for-recipes-by-edamam allows Stored XSS.This issue affects SEO, Nutrition and Print for Recipes by Edamam: from n/a through <= 3.3.
AplazadaMedia (6.5)0.36%—Boospotllc BOO RecipesAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes boo-recipes allows Stored XSS.This issue affects Boo Recipes: from n/a through <= 2.4.1.
AplazadaMedia (4.3)0.21%—Yummly Rich RecipesAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Yummly Yummly Rich Recipes yummly-rich-recipes allows Cross Site Request Forgery.This issue affects Yummly Rich Recipes: from n/a through <= 4.2.
AnalizadaMedia (5.4)0.37%—Tandoor Recipes28/1/202517/6/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.
AnalizadaMedia (6.5)0.52%—Tandoor Recipes28/1/202517/6/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
AnalizadaCrítica (9.9)3.6%💥 ExploitTandoor Recipes28/1/202517/6/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.
ModificadaMedia (6.5)0.43%—Tandoor Recipes1/3/202417/6/2026
Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.
ModificadaAlta (8.1)0.48%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0.
ModificadaMedia (6.1)0.38%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions.
ModificadaAlta (8.8)0.26%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions.
ModificadaBaja (3.5)0.85%—Tandoor Recipes21/6/202217/6/2026
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's…
ModificadaBaja (3.5)0.85%—Tandoor Recipes21/6/202217/6/2026
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A…
ModificadaBaja (3.5)0.85%—Tandoor Recipes21/6/202217/6/2026
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will…
ModificadaMedia (6.5)1.0%—Tandoor Recipes19/6/202217/6/2026
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.
ModificadaMedia (5.9)0.49%—Zipongo Inc. Healthy Recipes AND Grocery Deals15/5/201717/6/2026
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.1)2.2%—Recipes-writer Project Recipes-writer10/10/201617/6/2026
Reflected XSS in wordpress plugin recipes-writer v1.0.4
ModificadaAlta (7.5)2.3%💥 ExploitPhpmyrecipes Project Phpmyrecipes2/1/201517/6/2026
SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaAlta (7.5)1.3%💥 ExploitPhpmyrecipes Project Phpmyrecipes8/12/201417/6/2026
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the words_exact parameter.
ModificadaMedia (5.4)0.27%—Androidebookapp Healthy Lunch Diet Recipes19/10/201417/6/2026
The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Mbtcreations Detox Juicing Diet Recipes19/10/201417/6/2026
The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.0%💥 ExploitScriptsfeed Recipes Listing Portal2/11/201116/6/2026
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.5)3.9%💥 ExploitScriptsfeed Recipes Listing Portal12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
ModificadaAlta (7.5)0.99%💥 ExploitRecipescript Recipe Script18/5/200916/6/2026
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php.
ModificadaAlta (7.5)1.0%💥 ExploitJoomla COM RecipesMambo COM Recipes31/1/200816/6/2026
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
AnalizadaAlta (7.5)1.4%💥 ExploitSoftbizscripts Recipes Portal Script14/10/200716/6/2026
SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.
Orbitaley — Vulnerabilidades