Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 29/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <=… | |
| Aplazada | Media (6.9) | 0.11% | — | InfrarecorderAI | 26/4/2026 | 17/6/2026 | InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by importing a maliciously crafted text file. Attackers can create a text file containing 6000 bytes of data and import it through the Edit menu's Import function to trigger an application crash. | |
| Aplazada | Media (4.3) | 0.19% | — | NI Woocommerce Order ExportAI | 22/4/2026 | 17/6/2026 | The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_export_action() AJAX handler function. The handler processes settings updates when the 'page' parameter is set to… | |
| Aplazada | Media (4.3) | 0.11% | — | Zaytech Smart Online Order FOR CloverAI | 15/4/2026 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Online Food Ordering SystemAI | 8/4/2026 | 24/7/2026 | A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The attack may be performed from remote. The… | |
| Aplazada | Media (5.3) | 0.29% | — | Rustaurius Order TrackingAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3. | |
| Aplazada | Crítica (9.1) | 0.24% | — | Order Notification FOR WoocommerceAI | 1/4/2026 | 7/10/2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers. | |
| Modificada | Alta (8.6) | 0.21% | — | Uxgroupllc Voice Recorder | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Food Ordering SystemAI | 31/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available… | |
| Analizada | Media (5.5) | 0.57% | — | Carmelo Simple Food Order System | 29/3/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parameter Handler. The manipulation of the argument Status leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.5) | 0.57% | — | Carmelo Simple Food Order System | 28/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.57% | — | Carmelo Simple Food Order System | 28/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.3) | 0.39% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. | |
| Analizada | Alta (8.8) | 0.46% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands. | |
| Analizada | Alta (8.8) | 0.46% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious SQL commands. | |
| Modificada | Media (5.4) | 0.24% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a category. When an administrator… | |
| Aplazada | Media (5.5) | 0.48% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argument cuisines results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin.php of the component Admin Login Module. The manipulation of the argument Username results in sql injection. The attack may be performed from remote. The exploit is now public… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Food Ordering SystemAI | 26/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argument custom leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… |