Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.36%—Oretnom23 Online Food Ordering System12/1/202317/6/2026
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Category List Handler. The manipulation of the argument Reason with the input "><script>prompt(1)</script> leads to cross site scripting.…
ModificadaCrítica (9.8)0.54%—Oretnom23 Online Food Ordering System12/1/202317/6/2026
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image with the input <?php…
ModificadaCrítica (9.8)0.49%—Oretnom23 Online Food Ordering System12/1/202317/6/2026
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /fos/admin/ajax.php?action=login of the component Login Page. The manipulation of the argument Username leads to sql injection. It is possible to launch the…
ModificadaAlta (8.8)0.53%—Oracle Restaurant Menu - Food Ordering System - Table Reservation3/11/202217/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options…
ModificadaMedia (6.5)0.58%—Oracle Restaurant Menu - Food Ordering System - Table Reservation3/11/202217/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal…
ModificadaMedia (6.1)0.51%—Fast Food Ordering System Project Fast Food Ordering System1/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in /fastfood/purchase.php of Fast Food Ordering System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the customer parameter.
ModificadaAlta (7.5)0.82%—Fast Food Ordering System Project Fast Food Ordering System1/11/202217/6/2026
Fast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.
ModificadaMedia (5.4)0.36%—Oretnom23 Online Medicine Ordering System27/10/202217/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack can…
ModificadaCrítica (9.8)0.42%—Oretnom23 Online Medicine Ordering System27/10/202217/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. VDB-212346 is the identifier…
ModificadaCrítica (9.8)1.1%—Oretnom23 Online Food Ordering System2/9/202217/6/2026
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.
ModificadaAlta (7.5)0.93%—Online Ordering System Project Online Ordering System31/8/202217/6/2026
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
ModificadaAlta (7.2)1.4%—Online Ordering System Project Online Ordering System31/8/202217/6/2026
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.1)0.40%—Fast Food Ordering System Project Fast Food Ordering System27/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue affects some unknown processing of the file admin/?page=reports. The manipulation of the argument date leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-207425…
ModificadaAlta (8.8)0.74%—Fast Food Ordering System Project Fast Food Ordering System27/8/202217/6/2026
A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue is some unknown functionality of the file ffos/admin/reports/index.php. The manipulation of the argument date leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaMedia (5.4)0.54%—Fast Food Ordering System Project Fast Food Ordering System6/8/202217/6/2026
A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (5.4)0.66%—Simple Food Ordering System Project Simple Food Ordering System5/8/202217/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Food Ordering System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password with the input "><ScRiPt>alert(1)</sCrIpT> leads to cross site scripting. It is possible to initiate…
ModificadaMedia (5.4)0.53%—Fast Food Ordering System Project Fast Food Ordering System14/7/202217/6/2026
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System17/6/202217/6/2026
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System17/6/202217/6/2026
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
ModificadaCrítica (9.8)1.1%—Online Ordering System Project Online Ordering System17/6/202217/6/2026
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
ModificadaAlta (7.2)0.96%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.
ModificadaAlta (7.2)0.96%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=.
ModificadaAlta (7.2)0.96%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=.
ModificadaAlta (7.2)0.96%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category.
ModificadaAlta (7.2)0.96%—Fast Food Ordering System Project Fast Food Ordering System14/6/202217/6/2026
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=.