Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.49% | — | Zipongo Inc. Healthy Recipes AND Grocery Deals | 15/5/2017 | 17/6/2026 | The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.1) | 2.2% | — | Recipes-writer Project Recipes-writer | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin recipes-writer v1.0.4 | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Phpmyrecipes Project Phpmyrecipes | 2/1/2015 | 17/6/2026 | SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpmyrecipes Project Phpmyrecipes | 8/12/2014 | 17/6/2026 | SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the words_exact parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Androidebookapp Healthy Lunch Diet Recipes | 19/10/2014 | 17/6/2026 | The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mbtcreations Detox Juicing Diet Recipes | 19/10/2014 | 17/6/2026 | The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Brotherscripts Recipe Website | 8/7/2010 | 16/6/2026 | SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Todd Rogers Phprecipebook | 11/6/2010 | 16/6/2026 | SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL commands via the (1) base_id or (2) course_id parameter in a search action. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Jdtmmsm Ezrecipe-zee | 13/10/2009 | 16/6/2026 | Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Php-nuke Recipe Module | 14/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter. | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Recipescript Recipe Script | 18/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php. | |
| Modificada | Media (4.3) | 1.0% | — | Ex-designs World Recipe | 4/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to emailrecipe.aspx, (2) id parameter to recipedetail.aspx, and the (3) catid parameter to validatefieldlength.aspx. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | DAN Fletcher Recipe Script | 22/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Maian Recipe | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM RapidrecipeRapid-source Rapid Recipe | 13/6/2008 | 16/6/2026 | SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Recipe | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Recipe 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) header, (2) header2, (3) header3, (4) header4, (5) header5, (6) header6, (7) header7, (8) header8, and (9) header9 parameters. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Joomla Rapid Recipe | 20/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) user_id or (2) category_id parameter. NOTE: this might overlap CVE-2008-0754. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Joomla COM Rapidrecipe | 13/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomla COM RecipesMambo COM Recipes | 31/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Easysitenetwork Recipe Website Script | 25/1/2008 | 16/6/2026 | SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. | |
| Analizada | Alta (7.5) | 1.4% | 💥 Exploit | Softbizscripts Recipes Portal Script | 14/10/2007 | 16/6/2026 | SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Scriptmagix Recipes | 23/3/2007 | 16/6/2026 | SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Maian Recipe | 8/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. |