Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
892 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Restaurant Menu AND Food OrderingAI | 25/9/2026 | 25/9/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Baja (1.3) | 0.15% | — | Sfturing Hosp OrderAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may… | |
| Aplazada | Baja (2.1) | 0.16% | — | Sfturing Hosp OrderAI | 23/9/2026 | 24/9/2026 | A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.9) | 0.21% | — | Sfturing Hosp OrderAI | 23/9/2026 | 29/9/2026 | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation results in cleartext transmission of sensitive information. The attack can be… | |
| Aplazada | Baja (1.9) | 0.08% | — | Sfturing Hosp OrderAI | 23/9/2026 | 23/9/2026 | A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such manipulation leads to cleartext storage of sensitive information. The attack can only… | |
| Aplazada | Baja (2.9) | 0.26% | — | Sfturing Hosp OrderAI | 23/9/2026 | 23/9/2026 | A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It… | |
| Aplazada | Alta (7.2) | 1.0% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 26/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying… | |
| Aplazada | Media (6.2) | 0.16% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 24/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code… | |
| Aplazada | Media (5.3) | 0.36% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 24/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS… | |
| Aplazada | Media (6.5) | 0.21% | — | Openeye Apex Network Video RecorderAI | 22/9/2026 | 24/9/2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sfturing Hosp OrderAI | 22/9/2026 | 25/9/2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the component Public Search Handlers. The manipulation of the argument Search leads to cross site scripting. The attack can be initiated remotely.… | |
| Aplazada | Alta (7.5) | 0.50% | — | Nuuo Network Video RecorderAI | 18/9/2026 | 22/9/2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This… | |
| Aplazada | Alta (8.8) | 1.1% | — | Nuuo Network Video RecorderAI | 18/9/2026 | 22/9/2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. | |
| Aplazada | Crítica (9.4) | 1.2% | — | Webrecorder BrowsertrixAI | 17/9/2026 | 24/9/2026 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through… | |
| Aplazada | Baja (1.9) | 0.38% | — | Sourcecodester Online Food Ordering SystemAI | 16/9/2026 | 22/9/2026 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Oracle Order ManagementAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Order ManagementAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful… | |
| Aplazada | Alta (8.7) | 0.32% | — | Oracle Siebel Apps - Customer Order ManagementAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order… | |
| Aplazada | Alta (8.7) | 0.32% | — | Oracle Siebel Apps - Customer Order ManagementAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order… | |
| Aplazada | Alta (7.7) | 0.37% | — | Oracle Order ManagementAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 16/9/2026 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released… | |
| Pendiente de análisis | Alta (8.1) | 0.59% | — | Siam OrderingAI | 9/9/2026 | 14/9/2026 | Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator. | |
| Aplazada | Alta (8.8) | 0.51% | — | Siam Ordering Siam-serverAI | 9/9/2026 | 10/9/2026 | A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java). | |
| Aplazada | Media (5.5) | 0.56% | — | Sfturing Hosp OrderAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in… |