Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.47% | — | Yashpokharna2555 Restaurent-management-systemAI | 28/6/2026 | 29/6/2026 | A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Yashpokharna2555 Restaurent-management-systemAI | 28/6/2026 | 30/6/2026 | A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit is publicly… | |
| Aplazada | Alta (8.5) | 0.36% | — | Motopress Restaurant MenuAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest Everest FormsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Quick Interest SliderAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant MenuAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Motopress Restaurant MenuAI | 26/6/2026 | 5/10/2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | |
| Aplazada | Alta (8.7) | 0.49% | — | Capgo BackendAISupabase PostgrestAI | 23/6/2026 | 23/6/2026 | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries… | |
| Aplazada | Alta (8.6) | 0.39% | — | CapgoAIPostgrestAI | 23/6/2026 | 23/6/2026 | Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS… | |
| Aplazada | Media (6.9) | 0.39% | — | Supabase PostgrestAICapgoAI | 20/6/2026 | 24/6/2026 | Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauthenticated attacker using only the public Supabase API key… | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 20/6/2026 | 22/6/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows unauthenticated attackers to enumerate organizations and disclose billing status using the public sb_publishable key. Attackers can invoke these endpoints to determine… | |
| Aplazada | Alta (8.7) | 0.37% | — | CapgoAISupabaseAIPostgrestAI | 19/6/2026 | 22/6/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert… | |
| Aplazada | Alta (7.1) | 0.41% | — | CapgoAIPostgrestAI | 19/6/2026 | 22/6/2026 | Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing secrets and delivery… | |
| Analizada | Alta (8.8) | 0.49% | — | Wdmtech Vrestaurant | 19/6/2026 | 21/8/2026 | Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint with crafted SQL payloads in the keysearch… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Restaurant ZoneAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | |
| Aplazada | Crítica (9.9) | 0.46% | — | RestaurtAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Premium AGE Verification RestrictionAI | 17/6/2026 | 7/10/2026 | Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. | |
| Aplazada | Media (6.4) | 0.42% | — | Prestoplayer Presto PlayerAI | 12/6/2026 | 28/8/2026 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url… | |
| Analizada | Media (5.3) | 0.31% | — | Vmware Spring Data Rest | 10/6/2026 | 23/7/2026 | Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11;… | |
| Analizada | Media (5.3) | 0.33% | — | Vmware Spring Data Rest | 10/6/2026 | 23/7/2026 | Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5. | |
| Analizada | Alta (8.1) | 0.40% | 💥 PoC | Vmware Spring Data Rest | 10/6/2026 | 23/7/2026 | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expression without… | |
| Analizada | Alta (7.5) | 0.35% | — | Vmware Spring Data Rest | 10/6/2026 | 23/7/2026 | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0… | |
| Analizada | Media (5.9) | 0.29% | — | Broadcom Spring Rest Docs | 10/6/2026 | 23/7/2026 | When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. Affected versions:… | |
| Pendiente de análisis | Alta (8.7) | 0.35% | — | Purestorage Flasharray PurityAI | 9/6/2026 | 23/7/2026 | A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges. |