Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.34%—Bootstrapped WP Recipe Maker18/1/202417/6/2026
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (8.1)0.48%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0.
ModificadaAlta (7.1)0.22%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
ModificadaAlta (7.8)0.24%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
ModificadaAlta (8.8)0.21%—Easyrecipe Project Easyrecipe6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in EasyRecipe plugin <= 3.5.3251 versions.
ModificadaCrítica (9.8)0.74%—MY Food Recipe Project MY Food Recipe18/9/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.38%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions.
ModificadaCrítica (9.8)0.52%—Phpscriptpoint Recipepoint28/7/202317/6/2026
A vulnerability, which was classified as critical, was found in phpscriptpoint RecipePoint 1.9. This affects an unknown part of the file /recipe-result. The manipulation of the argument text/category/type/difficulty/cuisine/cooking_method leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaAlta (8.8)0.26%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions.
ModificadaMedia (5.4)0.53%—Bootstrapped WP Recipe Maker9/1/202317/6/2026
The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (5.4)0.51%—Blossomthemes Blossom Recipe Maker23/9/202217/6/2026
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress.
ModificadaCrítica (9.3)1.3%—Python-recipe-database Project Python-recipe-database11/7/202217/6/2026
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (6.5)0.64%—Jenkins Recipe30/6/202217/6/2026
Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
ModificadaAlta (8.8)0.94%—Jenkins Recipe30/6/202217/6/2026
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (8)0.49%—Jenkins Recipe30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.
ModificadaBaja (3.5)0.85%—Tandoor Recipes21/6/202217/6/2026
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's…
ModificadaBaja (3.5)0.85%—Tandoor Recipes21/6/202217/6/2026
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A…
ModificadaBaja (3.5)0.85%—Tandoor Recipes21/6/202217/6/2026
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will…
ModificadaMedia (6.5)1.0%—Tandoor Recipes19/6/202217/6/2026
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.
ModificadaMedia (6.1)0.73%—TRY MY Recipe Project TRY MY Recipe24/1/202217/6/2026
Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers to gain the PHPSESID or other unspecified impacts via the fullname parameter to the login_registration page.
ModificadaCrítica (9.8)1.9%—TRY MY Recipe Project TRY MY Recipe24/1/202217/6/2026
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.
ModificadaMedia (5.4)0.62%—Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor27/9/202117/6/2026
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site…
ModificadaMedia (6.1)0.83%—Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor27/9/202117/6/2026
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
ModificadaAlta (8.8)1.8%—Silverstripe MimevalidatorSilverstripe Recipe15/7/202017/6/2026
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as…
ModificadaMedia (5.4)0.75%—Bootstrapped WP Ultimate Recipe30/8/201917/6/2026
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
Orbitaley — Vulnerabilidades