Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering Script | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering Script | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering Script | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_deleted' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering Script | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the routers/add-ticket.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/details-router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.70% | — | Projectworlds Online Food Ordering System | 2/11/2023 | 17/6/2026 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (6.1) | 0.33% | — | Zaytech Smart Online Order FOR Clover | 31/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 versions. | |
| Modificada | Media (4.8) | 0.32% | — | Order Auto Complete FOR Woocommerce Project Order Auto Complete FOR Woocommerce | 18/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kardi Order auto complete for WooCommerce plugin <= 1.2.0 versions. | |
| Modificada | Media (4.3) | 0.40% | — | Oracle Communications Order AND Service Management | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: User Management). Supported versions that are affected are 7.4.0 and 7.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (4.3) | 0.41% | — | Oracle Enterprise Session Border Controller | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Web UI). Supported versions that are affected are 9.0-9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Session Border… | |
| Modificada | Alta (8.8) | 0.25% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions. | |
| Modificada | Alta (8.8) | 0.44% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 5/10/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of… | |
| Modificada | Crítica (9.8) | 0.48% | — | Oretnom23 Online Pizza Ordering System | 5/10/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The identifier of… | |
| Modificada | Crítica (9.8) | 3.9% | — | Unify Session Border Controller | 4/10/2023 | 17/6/2026 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | |
| Modificada | Alta (8.8) | 3.8% | — | Unify Session Border Controller | 4/10/2023 | 17/6/2026 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users. | |
| Modificada | Media (4.8) | 0.37% | — | Tychesoftwares Order Delivery Date FOR WP E-commerce | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 25/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | Food Ordering Website Project Food Ordering Website | 17/9/2023 | 17/6/2026 | A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… |