Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.46% | — | Everestthemes Everest Backup | 6/11/2024 | 17/6/2026 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain… | |
| Modificada | Media (5.4) | 0.24% | — | Crestaproject Cresta Addons FOR Elementor | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Cresta Addons for Elementor cresta-addons-for-elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through <= 1.0.9. | |
| Analizada | Media (6.9) | 0.65% | — | Carmelogarcia Restaurant Order System | 3/11/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (6.3) | 0.39% | — | Prestoplayer Presto PlayerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Presto Player: from n/a through 3.0.2. | |
| Aplazada | Media (5.3) | 0.38% | — | Wpbackitup Backup AND RestoreAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPBackItUp Backup and Restore WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Backup and Restore WordPress: from n/a through 1.50. | |
| Aplazada | Media (5.4) | 0.32% | — | Wpbackitup Backup AND RestoreAI | 1/11/2024 | 17/6/2026 | Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows . This issue affects Backup and Restore WordPress: from n/a through 1.50. | |
| Aplazada | Media (5.4) | 0.30% | — | Redi Restaurant ReservationAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422. | |
| Modificada | Crítica (9.8) | 0.51% | — | Vivektamrakar WP Rest API FNS | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Upload a Web Shell to a Web Server.This issue affects WP REST API FNS: from n/a through <= 1.0.0. | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Vivektamrakar WP Rest API FNS | 20/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.3) | 0.36% | — | Coingate PluginAIPrestashopAI | 17/10/2024 | 17/6/2026 | A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The manipulation leads to business logic errors. The attack may be… | |
| Aplazada | Alta (7.1) | 0.27% | — | Rconnect305 Restaurant Reservations WidgetAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restaurant Reservations Widget restaurantconnect-reswidget allows Reflected XSS.This issue affects Restaurant Reservations Widget: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.39% | — | Redi Restaurant ReservationAI | 17/10/2024 | 17/6/2026 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.5) | 0.52% | — | PCS Engineering Preston CinemaAI | 14/10/2024 | 17/6/2026 | An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Analizada | Media (6.9) | 0.70% | — | Code-projects Restaurant Reservation System | 10/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.3) | 0.65% | — | Resteasy-netty4AINettyAI | 8/10/2024 | 17/6/2026 | A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Purestorage FlasharrayAI | 8/10/2024 | 17/6/2026 | A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation. | |
| Modificada | Media (5.4) | 0.31% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows Stored XSS.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through <= 1.5.5. | |
| Analizada | Media (5.3) | 0.59% | — | Code-projects Restaurant Reservation System | 2/10/2024 | 17/6/2026 | A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter2.php. The manipulation of the argument from/to leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.39% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 2/10/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for… | |
| Analizada | Media (6.9) | 0.80% | — | Code-projects Restaurant Reservation System | 1/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.80% | — | Code-projects Restaurant Reservation System | 1/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Alta (8.7) | 0.72% | — | Zope Restrictedpython | 30/9/2024 | 17/6/2026 | RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require… | |
| Modificada | Crítica (9.8) | 0.59% | — | Jianbo Rest API TO Miniprogram | 25/9/2024 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for… | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Jianbo Rest API TO Miniprogram | 25/9/2024 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Analizada | Alta (8.8) | 0.63% | — | Purestorage Purity//faPurestorage Purity//fb | 23/9/2024 | 17/6/2026 | A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration. |