Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.34% | — | Bootstrapped WP Recipe Maker | 18/1/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.1) | 0.48% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0. | |
| Modificada | Alta (7.1) | 0.22% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service. | |
| Modificada | Alta (7.8) | 0.24% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine. | |
| Modificada | Alta (8.8) | 0.21% | — | Easyrecipe Project Easyrecipe | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in EasyRecipe plugin <= 3.5.3251 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | MY Food Recipe Project MY Food Recipe | 18/9/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.38% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions. | |
| Modificada | Crítica (9.8) | 0.52% | — | Phpscriptpoint Recipepoint | 28/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in phpscriptpoint RecipePoint 1.9. This affects an unknown part of the file /recipe-result. The manipulation of the argument text/category/type/difficulty/cuisine/cooking_method leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Bootstrapped WP Recipe Maker | 9/1/2023 | 17/6/2026 | The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.51% | — | Blossomthemes Blossom Recipe Maker | 23/9/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress. | |
| Modificada | Crítica (9.3) | 1.3% | — | Python-recipe-database Project Python-recipe-database | 11/7/2022 | 17/6/2026 | The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.5) | 0.64% | — | Jenkins Recipe | 30/6/2022 | 17/6/2026 | Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML. | |
| Modificada | Alta (8.8) | 0.94% | — | Jenkins Recipe | 30/6/2022 | 17/6/2026 | Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8) | 0.49% | — | Jenkins Recipe | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML. | |
| Modificada | Baja (3.5) | 0.85% | — | Tandoor Recipes | 21/6/2022 | 17/6/2026 | In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's… | |
| Modificada | Baja (3.5) | 0.85% | — | Tandoor Recipes | 21/6/2022 | 17/6/2026 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A… | |
| Modificada | Baja (3.5) | 0.85% | — | Tandoor Recipes | 21/6/2022 | 17/6/2026 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will… | |
| Modificada | Media (6.5) | 1.0% | — | Tandoor Recipes | 19/6/2022 | 17/6/2026 | In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information. | |
| Modificada | Media (6.1) | 0.73% | — | TRY MY Recipe Project TRY MY Recipe | 24/1/2022 | 17/6/2026 | Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers to gain the PHPSESID or other unspecified impacts via the fullname parameter to the login_registration page. | |
| Modificada | Crítica (9.8) | 1.9% | — | TRY MY Recipe Project TRY MY Recipe | 24/1/2022 | 17/6/2026 | SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page. | |
| Modificada | Media (5.4) | 0.62% | — | Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor | 27/9/2021 | 17/6/2026 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site… | |
| Modificada | Media (6.1) | 0.83% | — | Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor | 27/9/2021 | 17/6/2026 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 1.8% | — | Silverstripe MimevalidatorSilverstripe Recipe | 15/7/2020 | 17/6/2026 | Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as… | |
| Modificada | Media (5.4) | 0.75% | — | Bootstrapped WP Ultimate Recipe | 30/8/2019 | 17/6/2026 | The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. |