Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.39% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may… | |
| Analizada | Media (5.5) | 0.53% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.php. This manipulation of the argument cname causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2.1) | 0.39% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The manipulation of the argument pname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Food Ordering System | 27/10/2025 | 1/10/2026 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Media (6.5) | 0.32% | — | Vanquish Woocommerce Orders Customers ExporterAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Orders & Customers Exporter: from n/a through <= 5.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Weboccult Technologies PVT LTD Email Attachment BY Order Status ProductsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status & Products: from n/a… | |
| Aplazada | Crítica (9.3) | 0.49% | — | Cozyvision SMS Alert Order NotificationsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5. | |
| Aplazada | Media (4.3) | 0.19% | — | Flexible Refund AND Return OrderAI | 22/10/2025 | 17/6/2026 | The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.38 via the save_refund_request() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit refund requests for… | |
| Modificada | Media (4.3) | 0.47% | — | Fortinet FortimailFortinet FortimanagerFortinet Fortimanager CloudFortinet Fortindr+8 | 14/10/2025 | 17/6/2026 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR… | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file /addcategory.php. The manipulation of the argument cname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the file /addproduct.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Projectworlds Online Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the argument Status causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 0.38% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument Category results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Food Ordering System | 11/10/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of the argument cname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Media (4.6) | 0.17% | — | Samsung Voice Recorder | 10/10/2025 | 17/6/2026 | Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen. | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Simple Food Ordering System | 7/10/2025 | 30/9/2026 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.5) | 3.9% | 💥 Exploit | OrderconvoAI | 7/10/2025 | 17/6/2026 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack | |
| Aplazada | Alta (8.4) | 0.16% | — | Denso TEN Drive Recorder ViewerAI | 6/10/2025 | 17/6/2026 | The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer. | |
| Aplazada | Media (4.3) | 0.13% | — | VM Menu ReorderAI | 27/9/2025 | 17/6/2026 | The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the vm_set_to_default function. This makes it possible for unauthenticated attackers to reset all menu reordering settings via… | |
| Analizada | Baja (2) | 0.24% | — | Fabian Simple Food Ordering System | 23/9/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /ordersimple/order.php. The manipulation of the argument ID leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpswings Upsell Order Bump Offer FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce upsell-order-bump-offer-for-woocommerce allows Stored XSS.This issue affects Upsell Order Bump Offer for WooCommerce: from n/a through <= 3.0.7. | |
| Aplazada | Media (5.9) | 0.22% | — | Tomas Cordero Safety ExitAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit safety-exit allows Stored XSS.This issue affects Safety Exit: from n/a through <= 1.8.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Ericsson Catalog ManagerAIEricsson Order CareAI | 18/9/2025 | 17/6/2026 | Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue. | |
| Analizada | Media (5.4) | 0.22% | — | Carmelo Food Ordering Review System | 16/9/2025 | 17/6/2026 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information. |