Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.49% | — | Oretnom23 Online Food Ordering System | 6/2/2023 | 17/6/2026 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php. | |
| Modificada | Media (6.1) | 0.49% | — | Oretnom23 Online Food Ordering System | 6/2/2023 | 17/6/2026 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php. | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Food Ordering System | 20/1/2023 | 17/6/2026 | Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0. | |
| Modificada | Crítica (9.8) | 0.92% | — | Oretnom23 Online Food Ordering System | 17/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file admin/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.5) | 0.60% | — | Online Food Ordering System V2 Project Online Food Ordering System V2 | 15/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Food Ordering System. This vulnerability affects unknown code of the file admin_class.php of the component Login Module. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.60% | — | Online Food Ordering System V2 Project Online Food Ordering System V2 | 15/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Food Ordering System. This affects an unknown part of the file admin_class.php of the component Signup Module. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (7.5) | 0.60% | — | Online Food Ordering System V2 Project Online Food Ordering System V2 | 15/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System. It has been rated as critical. Affected by this issue is some unknown functionality of the file view_prod.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.36% | — | Oretnom23 Online Food Ordering System | 12/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Category List Handler. The manipulation of the argument Reason with the input "><script>prompt(1)</script> leads to cross site scripting.… | |
| Modificada | Crítica (9.8) | 0.54% | — | Oretnom23 Online Food Ordering System | 12/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image with the input <?php… | |
| Modificada | Crítica (9.8) | 0.49% | — | Oretnom23 Online Food Ordering System | 12/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /fos/admin/ajax.php?action=login of the component Login Page. The manipulation of the argument Username leads to sql injection. It is possible to launch the… | |
| Modificada | Alta (8.8) | 0.53% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 3/11/2022 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options… | |
| Modificada | Media (6.5) | 0.58% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 3/11/2022 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal… | |
| Modificada | Media (6.1) | 0.51% | — | Fast Food Ordering System Project Fast Food Ordering System | 1/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /fastfood/purchase.php of Fast Food Ordering System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the customer parameter. | |
| Modificada | Alta (7.5) | 0.82% | — | Fast Food Ordering System Project Fast Food Ordering System | 1/11/2022 | 17/6/2026 | Fast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Oretnom23 Online Food Ordering System | 2/9/2022 | 17/6/2026 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=. | |
| Modificada | Media (6.1) | 0.40% | — | Fast Food Ordering System Project Fast Food Ordering System | 27/8/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue affects some unknown processing of the file admin/?page=reports. The manipulation of the argument date leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-207425… | |
| Modificada | Alta (8.8) | 0.74% | — | Fast Food Ordering System Project Fast Food Ordering System | 27/8/2022 | 17/6/2026 | A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue is some unknown functionality of the file ffos/admin/reports/index.php. The manipulation of the argument date leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.54% | — | Fast Food Ordering System Project Fast Food Ordering System | 6/8/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.66% | — | Simple Food Ordering System Project Simple Food Ordering System | 5/8/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Food Ordering System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password with the input "><ScRiPt>alert(1)</sCrIpT> leads to cross site scripting. It is possible to initiate… | |
| Modificada | Media (5.4) | 0.53% | — | Fast Food Ordering System Project Fast Food Ordering System | 14/7/2022 | 17/6/2026 | Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category. | |
| Modificada | Alta (7.2) | 0.96% | — | Fast Food Ordering System Project Fast Food Ordering System | 14/6/2022 | 17/6/2026 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=. | |
| Modificada | Alta (7.2) | 0.96% | — | Fast Food Ordering System Project Fast Food Ordering System | 14/6/2022 | 17/6/2026 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=. | |
| Modificada | Alta (7.2) | 0.96% | — | Fast Food Ordering System Project Fast Food Ordering System | 14/6/2022 | 17/6/2026 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=. | |
| Modificada | Alta (7.2) | 0.96% | — | Fast Food Ordering System Project Fast Food Ordering System | 14/6/2022 | 17/6/2026 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category. | |
| Modificada | Alta (7.2) | 0.96% | — | Fast Food Ordering System Project Fast Food Ordering System | 14/6/2022 | 17/6/2026 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=. |