Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

1172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.2%—Microsoft Typed-rest-client26/4/202317/6/2026
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with…
ModificadaAlta (8.8)1.7%💥 PoCPrestashop25/4/202317/6/2026
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.
ModificadaCrítica (9.9)1.0%—Prestashop25/4/202317/6/2026
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML…
ModificadaMedia (6.5)0.86%—Prestashop25/4/202317/6/2026
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user…
ModificadaAlta (8.8)3.2%💥 ExploitHockeycomputindo Bang Resto24/4/202317/6/2026
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.
ModificadaMedia (4.8)1.9%💥 ExploitHockeycomputindo Bang Resto24/4/202317/6/2026
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function.
ModificadaAlta (7.2)0.69%—Transbank Webpay Rest16/4/202317/6/2026
Auth. (admin+) SQL Injection (SQLi) vulnerability in TransbankDevelopers Transbank Webpay REST plugin <= 1.6.6 versions.
ModificadaMedia (4.8)0.39%—Wpeverest User Registration6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.
ModificadaCrítica (9.8)1.2%—Myprestamodules Frequently Asked Questions Page31/3/202317/6/2026
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.
ModificadaAlta (7.2)1.1%—Gladinet Centrestack31/3/202317/6/2026
An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to the server.
ModificadaCrítica (9.8)1.2%—Gladinet Centrestack31/3/202317/6/2026
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full authentication bypass.
ModificadaCrítica (9.8)0.62%—Prestashop EO Tags21/3/202317/6/2026
El paquete de etiquetas eo_tags antes de 1.4.19 para PrestaShop permite la inyección de SQL a través de una cookie _ga manipulada.
ModificadaCrítica (9.8)0.87%—Prestashop EO Tags21/3/202317/6/2026
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
ModificadaAlta (8.8)0.90%—Prestashop Advanced Reviews14/3/202317/6/2026
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)0.89%—Prestashop DPD France13/3/202317/6/2026
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
ModificadaAlta (8.8)0.22%—Prestashop13/3/202317/6/2026
PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF…
ModificadaMedia (5.9)0.35%—Icepay Rest API12/3/202317/6/2026
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper validation of integrity check value. The attack can be launched…
ModificadaAlta (8.8)0.88%—Prestashop XEN Forum6/3/202317/6/2026
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
ModificadaMedia (5.5)0.26%—Redhat ResteasyNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation17/2/202317/6/2026
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
ModificadaMedia (5.4)0.67%—Oracle Restaurant Menu - Food Ordering System - Table Reservation6/2/202317/6/2026
The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaCrítica (9.8)0.93%—Bangresto Project Bangresto31/1/202317/6/2026
Vulnerabilidad de inyección SQL en Bangresto 1.0 a través del parámetro itemID.
ModificadaMedia (5.4)0.60%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
El complemento Quick Restaurant Menu para WordPress es vulnerable a la omisión de autorización debido a una falta de verificación de capacidad en sus acciones AJAX en versiones hasta la 2.0.2 incluida. Esto hace posible que los atacantes autenticados, con permisos de nivel de suscriptor y superiores, invoquen aquellas…
ModificadaMedia (4.3)0.36%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
El complemento Quick Restaurant Menu para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 2.0.2 incluida. Esto se debe a una validación nonce faltante o incorrecta en sus acciones AJAX. Esto hace posible que atacantes no autenticados actualicen elementos del menú; a través de una solicitud…
ModificadaMedia (4.8)0.54%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
El complemento Quick Restaurant Menu para WordPress es vulnerable a cross-site scripting almacenado a través de sus parámetros de configuración en versiones hasta la 2.0.2 incluida debido a una sanitización de entrada y un escape de salida insuficientes. Esto hace posible que atacantes autenticados, con permisos de…
ModificadaMedia (4.3)0.65%—Thingsforrestaurants Quick Restaurant Menu27/1/202317/6/2026
El complemento Quick Restaurant Menu para WordPress es vulnerable a Insecure Direct Object Reference en versiones hasta la 2.0.2 incluida. Esto se debe al hecho de que durante la eliminación/modificación de un elemento de menú, el complemento no verifica que el ID de publicación proporcionado a la acción AJAX sea de…