Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.47% | — | Carmelo Simple Food Order System | 22/3/2026 | 17/6/2026 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Status results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.67% | — | Carmelo Simple Food Order System | 22/3/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories accessible. It is possible to initiate… | |
| Aplazada | Media (4.3) | 0.14% | — | WP Posts Re-orderAI | 21/3/2026 | 17/6/2026 | The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the `cpt_plugin_options()` function. This makes it possible for unauthenticated attackers to update the plugin settings including capability,… | |
| Analizada | Baja (2.1) | 0.50% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulation of the argument Supplier_Name leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.51% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argument First_Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made… | |
| Analizada | Baja (2) | 0.51% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_edit_menu.php. Performing a manipulation of the argument product_name results in sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2) | 0.51% | — | Adonesevangelista Online Frozen Foods Ordering System | 20/3/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such manipulation of the argument product_name leads to sql injection. The attack may be performed from remote. The exploit… | |
| Analizada | Media (5.5) | 0.57% | — | Carmelo Simple Food Order System | 17/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/add-item.php. Such manipulation of the argument price leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be… | |
| Aplazada | Media (5.4) | 0.29% | — | Cozyvision SMS Alert Order NotificationsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.9.0. | |
| Analizada | Media (4) | 0.08% | — | Fortinet FortivoiceFortinet FortirecorderFortinet Fortimail | 10/3/2026 | 17/6/2026 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions,… | |
| Aplazada | Alta (7.5) | 0.41% | — | Vanquish Woocommerce Order DetailsAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Order Details: from n/a through <= 3.1. | |
| Modificada | Crítica (9.8) | 0.52% | — | Carmelo Simple Food Order System | 2/3/2026 | 17/6/2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Carmelo Simple Food Order System | 2/3/2026 | 17/6/2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Carmelo Simple Food Order System | 2/3/2026 | 17/6/2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Carmelo Simple Food Order System | 2/3/2026 | 17/6/2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. | |
| Analizada | Media (5.3) | 0.53% | — | Go2ismail Asp.net-core-inventory-order-management-system | 26/2/2026 | 17/6/2026 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is… | |
| Analizada | Baja (2.1) | 0.71% | — | Go2ismail Asp.net-core-inventory-order-management-system | 26/2/2026 | 17/6/2026 | A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (1.9) | 0.24% | — | Codeastro Food Ordering System | 25/2/2026 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Food Ordering System 1.0. This affects an unknown function of the file food_ordering.exe. Such manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (1.3) | 0.70% | 💥 PoC | Higuma Webaudiorecorder.js | 23/2/2026 | 17/6/2026 | A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the attack… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Order UP Online Ordering SystemAI | 23/2/2026 | 17/6/2026 | SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request. | |
| Aplazada | Alta (7.5) | 0.34% | — | Mdalabar WOO Order Delivery Time LiteAI | 20/2/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2. | |
| Aplazada | Alta (8.8) | 0.62% | — | OrderableAI | 19/2/2026 | 17/6/2026 | The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'install_plugin' function in all versions up to, and including, 1.20.0. This makes it possible for authenticated… | |
| Aplazada | Baja (2.7) | 0.33% | — | Oneclick Chat TO OrderAI | 19/2/2026 | 17/6/2026 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.24% | — | Order Splitter FOR WoocommerceAI | 18/2/2026 | 17/6/2026 | The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wos_troubleshooting' AJAX endpoint in all versions up to, and including, 5.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.30% | — | Wamate Confirm Order ConfirmationAI | 11/2/2026 | 17/6/2026 | The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level… |