Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

314 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.31%—Paniel Mwaura McarfixAI30/10/202517/6/2026
mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper access control vulnerabilities. Attackers may bypass verification to arbitrarily register accounts, and by tampering with sequential numeric IDs, gain unauthorized access to user data and groups.…
AplazadaMedia (6.4)0.19%—WP Restaurant ListingsAI22/10/202517/6/2026
The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter of the restaurant_summary shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaMedia (6.5)0.27%—Rajvi-patel-22 Restaurant-management-system-dbms-project20/10/202517/6/2026
There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through specially crafted SQL query strings.
AnalizadaMedia (5.8)0.39%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.
AnalizadaCrítica (9.9)0.50%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.
AnalizadaMedia (5.8)0.51%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.
AnalizadaMedia (5.8)0.38%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path.
AnalizadaAlta (7.7)0.54%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
AnalizadaCrítica (9.9)0.72%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
AnalizadaAlta (7.7)0.46%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.
AnalizadaAlta (8.6)0.32%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
AnalizadaAlta (8.6)0.49%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.
AnalizadaMedia (5.8)0.39%—RBI Restaurant Brands International Assistant17/10/202530/9/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.
AnalizadaBaja (2.1)0.35%—Phpjabbers Restaurant Menu Maker23/9/202517/6/2026
A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and…
AplazadaMedia (5.9)0.22%—Will.i.am Simple Restaurant MenuAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will.I.am Simple Restaurant Menu simple-restaurant-menu allows Stored XSS.This issue affects Simple Restaurant Menu: from n/a through <= 1.2.
AplazadaMedia (5.9)0.33%—E4jvikwp VikrestaurantsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Stored XSS.This issue affects VikRestaurants: from n/a through <= 1.5.1.
AplazadaAlta (7.1)0.34%—E4jvikwp VikrestaurantsAI22/9/202530/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5.
AplazadaMedia (6.5)0.21%—Best Restaurant Menu BY PricelistoAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto allows Stored XSS.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.3.
AplazadaMedia (4.3)0.16%—Easy Restaurant Menu ManagerAI13/8/202517/6/2026
The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the nsc_eprm_save_menu() function. This makes it possible for unauthenticated attackers to upload a menu file via a…
AplazadaMedia (4.3)0.15%—CBX Restaurant BookingAI11/8/202517/6/2026
The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (7.8)0.24%—Carmelogarcia Restaurant Order System1/8/20255/7/2026
SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file
AplazadaMedia (5.4)0.14%—Motopress Mp-restaurant-menuAI16/7/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6.
AplazadaMedia (6.4)0.26%—Easy Restaurant Menu ManagerAI4/7/202517/6/2026
The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_eprm_menu_link shortcode in versions up to, and including 2.0.1, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (5.5)0.49%—Carmelogarcia Restaurant Order System16/6/202517/6/2026
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (5.5)0.48%—Carmelogarcia Restaurant Order System16/6/202517/6/2026
A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerability affects unknown code of the file /payment.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…