Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.64%—Purestorage Purity//fa23/9/202417/6/2026
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
AnalizadaAlta (7.2)0.47%—Purestorage Purity//fa23/9/202417/6/2026
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
AnalizadaCrítica (9.8)0.60%—Purestorage Purity//fa23/9/202417/6/2026
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
AnalizadaCrítica (9.8)0.95%—Purestorage Purity//fa23/9/202417/6/2026
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
AnalizadaMedia (5.3)0.57%—Code-projects Restaurant Reservation System22/9/202417/6/2026
A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.74%—Code-projects Restaurant Reservation System22/9/202417/6/2026
A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaAlta (7.5)0.37%—Netiq Identity Manager Rest Driver12/9/202417/6/2026
Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200.
AnalizadaAlta (8.8)0.54%—Adonesevangelista Restaurant Management System5/9/202417/6/2026
itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
AnalizadaAlta (7.8)0.32%—Restsharp29/8/202417/6/2026
RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The same applies to `RestRequest.AddOrUpdateHeader` and `RestClient.AddDefaultHeader`. The way HTTP headers are added to a request is via the…
AnalizadaAlta (8.8)1.2%💥 PoCPricelisto Great Restaurant Menu WP29/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1.
AnalizadaMedia (4.3)0.18%—Wpbackitup Backup AND Restore Wordpress26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.
ModificadaAlta (8.1)1.3%💥 PoCPrestashop12/8/202417/6/2026
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to…
AnalizadaMedia (5.1)0.46%—Adonesevangelista Restaurant Management System31/7/202417/6/2026
A vulnerability was found in itsourcecode Alton Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_save.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.1)0.54%—Adonesevangelista Restaurant Management System31/7/202417/6/2026
A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/menu.php of the component Add a Menu. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The…
AnalizadaMedia (5.1)0.60%—Adonesevangelista Restaurant Management System30/7/202417/6/2026
A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/member_save.php. The manipulation of the argument last/first leads to sql injection. The attack can be launched remotely. The exploit has…
ModificadaMedia (5.1)0.60%—Adonesevangelista Restaurant Management System30/7/202417/6/2026
A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an unknown function of the file /admin/category_save.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…
ModificadaMedia (5.1)0.65%—Adonesevangelista Restaurant Management System30/7/202417/6/2026
A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issue affects some unknown processing of the file /reservation_status.php. The manipulation of the argument rcode leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.65%—Adonesevangelista Restaurant Management System30/7/202417/6/2026
A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AplazadaCrítica (9.8)0.51%—Hangzhou Xiongwei Technology Development Restaurant Digital Comprehensive Management PlatformAI26/7/202417/6/2026
An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.
AplazadaAlta (7.5)0.39%—Paypal OfficialAIPrestashopAI26/7/202417/6/2026
In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment in case of disabled webhooks can be…
AnalizadaMedia (5.9)0.56%—Openresty23/7/202417/6/2026
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of service with relatively…
ModificadaMedia (5.4)0.24%—Auburnforest Blogmentor22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AuburnForest Blogmentor – Blog Layouts for Elementor allows Stored XSS.This issue affects Blogmentor – Blog Layouts for Elementor: from n/a through 1.5.
ModificadaMedia (5.4)0.25%—Nicdarkthemes Restaurant Food22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 2.0.
AplazadaCrítica (9.3)0.38%—Purestorage FlashbladeAI17/7/202417/6/2026
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
AplazadaCrítica (9)0.67%—EverestAI10/7/202417/6/2026
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.