Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Microsoft Typed-rest-client | 26/4/2023 | 17/6/2026 | typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with… | |
| Modificada | Alta (8.8) | 1.7% | 💥 PoC | Prestashop | 25/4/2023 | 17/6/2026 | PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds. | |
| Modificada | Crítica (9.9) | 1.0% | — | Prestashop | 25/4/2023 | 17/6/2026 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML… | |
| Modificada | Media (6.5) | 0.86% | — | Prestashop | 25/4/2023 | 17/6/2026 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user… | |
| Modificada | Alta (8.8) | 3.2% | 💥 Exploit | Hockeycomputindo Bang Resto | 24/4/2023 | 17/6/2026 | Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter. | |
| Modificada | Media (4.8) | 1.9% | 💥 Exploit | Hockeycomputindo Bang Resto | 24/4/2023 | 17/6/2026 | Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function. | |
| Modificada | Alta (7.2) | 0.69% | — | Transbank Webpay Rest | 16/4/2023 | 17/6/2026 | Auth. (admin+) SQL Injection (SQLi) vulnerability in TransbankDevelopers Transbank Webpay REST plugin <= 1.6.6 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Wpeverest User Registration | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | Myprestamodules Frequently Asked Questions Page | 31/3/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component. | |
| Modificada | Alta (7.2) | 1.1% | — | Gladinet Centrestack | 31/3/2023 | 17/6/2026 | An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to the server. | |
| Modificada | Crítica (9.8) | 1.2% | — | Gladinet Centrestack | 31/3/2023 | 17/6/2026 | An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full authentication bypass. | |
| Modificada | Crítica (9.8) | 0.62% | — | Prestashop EO Tags | 21/3/2023 | 17/6/2026 | El paquete de etiquetas eo_tags antes de 1.4.19 para PrestaShop permite la inyección de SQL a través de una cookie _ga manipulada. | |
| Modificada | Crítica (9.8) | 0.87% | — | Prestashop EO Tags | 21/3/2023 | 17/6/2026 | The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. | |
| Modificada | Alta (8.8) | 0.90% | — | Prestashop Advanced Reviews | 14/3/2023 | 17/6/2026 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.89% | — | Prestashop DPD France | 13/3/2023 | 17/6/2026 | PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. | |
| Modificada | Alta (8.8) | 0.22% | — | Prestashop | 13/3/2023 | 17/6/2026 | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF… | |
| Modificada | Media (5.9) | 0.35% | — | Icepay Rest API | 12/3/2023 | 17/6/2026 | A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper validation of integrity check value. The attack can be launched… | |
| Modificada | Alta (8.8) | 0.88% | — | Prestashop XEN Forum | 6/3/2023 | 17/6/2026 | In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. | |
| Modificada | Media (5.5) | 0.26% | — | Redhat ResteasyNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 17/2/2023 | 17/6/2026 | In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user. | |
| Modificada | Media (5.4) | 0.67% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 6/2/2023 | 17/6/2026 | The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 0.93% | — | Bangresto Project Bangresto | 31/1/2023 | 17/6/2026 | Vulnerabilidad de inyección SQL en Bangresto 1.0 a través del parámetro itemID. | |
| Modificada | Media (5.4) | 0.60% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | El complemento Quick Restaurant Menu para WordPress es vulnerable a la omisión de autorización debido a una falta de verificación de capacidad en sus acciones AJAX en versiones hasta la 2.0.2 incluida. Esto hace posible que los atacantes autenticados, con permisos de nivel de suscriptor y superiores, invoquen aquellas… | |
| Modificada | Media (4.3) | 0.36% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | El complemento Quick Restaurant Menu para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 2.0.2 incluida. Esto se debe a una validación nonce faltante o incorrecta en sus acciones AJAX. Esto hace posible que atacantes no autenticados actualicen elementos del menú; a través de una solicitud… | |
| Modificada | Media (4.8) | 0.54% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | El complemento Quick Restaurant Menu para WordPress es vulnerable a cross-site scripting almacenado a través de sus parámetros de configuración en versiones hasta la 2.0.2 incluida debido a una sanitización de entrada y un escape de salida insuficientes. Esto hace posible que atacantes autenticados, con permisos de… | |
| Modificada | Media (4.3) | 0.65% | — | Thingsforrestaurants Quick Restaurant Menu | 27/1/2023 | 17/6/2026 | El complemento Quick Restaurant Menu para WordPress es vulnerable a Insecure Direct Object Reference en versiones hasta la 2.0.2 incluida. Esto se debe al hecho de que durante la eliminación/modificación de un elemento de menú, el complemento no verifica que el ID de publicación proporcionado a la acción AJAX sea de… |