Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Iresturant Project Iresturant | 25/1/2022 | 17/6/2026 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation. | |
| Modificada | Crítica (9.8) | 1.3% | — | Iresturant Project Iresturant | 25/1/2022 | 17/6/2026 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration. | |
| Modificada | Media (5.4) | 0.59% | — | Iresturant Project Iresturant | 12/1/2022 | 17/6/2026 | MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. | |
| Modificada | Crítica (9.8) | 3.4% | — | Iresturant Project Iresturant | 20/12/2021 | 17/6/2026 | RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely | |
| Modificada | Media (5.4) | 0.66% | — | Iresturant Project Iresturant | 20/12/2021 | 17/6/2026 | Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field |