Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.38% | — | Sourcecodester Online Food Ordering SystemAI | 16/9/2026 | 22/9/2026 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 16/9/2026 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 26/8/2026 | 29/8/2026 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.41% | — | Sililawijesinghe Food Ordering SystemAI | 25/8/2026 | 28/8/2026 | A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 24/8/2026 | A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 26/8/2026 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 24/8/2026 | A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 27/8/2026 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 24/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 25/8/2026 | A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Simple Online Food Ordering SystemAI | 20/8/2026 | 24/8/2026 | A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 21/8/2026 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Online Food Ordering SystemAI | 19/8/2026 | 21/8/2026 | A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.51% | — | Sourcecodester Simple Food Ordering SystemAI | 29/6/2026 | 29/6/2026 | A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.30% | — | Sourcecodester Online Food Ordering SystemAI | 3/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Online Food Ordering SystemAI | 8/4/2026 | 24/7/2026 | A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The attack may be performed from remote. The… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Food Ordering SystemAI | 31/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available… | |
| Analizada | Alta (8.3) | 0.39% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. | |
| Analizada | Alta (8.8) | 0.46% | — | Oretnom23 Online Food Ordering System | 27/3/2026 | 17/6/2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands. |