Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
314 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 5/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24. | |
| Aplazada | Alta (7.1) | 0.16% | — | Five Star Restaurant ReviewsAI | 1/10/2026 | 1/10/2026 | The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in… | |
| Aplazada | Baja (2.1) | 0.37% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.33% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 2/10/2026 | A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The… | |
| Aplazada | Alta (7.2) | 0.24% | — | Restaurant Menu AND Food OrderingAI | 25/9/2026 | 25/9/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Baja (2.1) | 0.24% | — | Adithyayelloju Restaurant Management SystemAI | 22/9/2026 | 23/9/2026 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search Form. This manipulation of the argument s1 causes sql injection. The attack can be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Adithyayelloju Restaurant Management SystemAI | 20/9/2026 | 22/9/2026 | A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/members/price results in sql injection. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.33% | — | Adithyayelloju Restaurant-management-systemAI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate… | |
| Aplazada | Baja (2.1) | 1.1% | — | 0-gaurav-0 Nexus-mcpAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipulation of the argument url results in command injection. The attack may be performed… | |
| Aplazada | Media (5.3) | 0.16% | — | Restaurant Menu AND Food OrderingAI | 4/9/2026 | 8/9/2026 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment. | |
| Aplazada | Alta (8.1) | 0.47% | — | Motopress Restaurant MenuAI | 18/8/2026 | 20/8/2026 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 6/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending… | |
| Aplazada | Alta (7.5) | 0.39% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the… | |
| Aplazada | Alta (7.3) | 0.12% | — | Asus Aura SyncAI | 17/7/2026 | 29/9/2026 | **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the… | |
| Aplazada | Alta (8.5) | 0.11% | — | Asus Aura Wallpaper ServiceAI | 15/7/2026 | 15/7/2026 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this… | |
| Aplazada | Alta (7.5) | 0.51% | — | Saurabhsharma Newsplus ShortcodesAIPHPAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0. | |
| Aplazada | Media (5.5) | 0.69% | — | Jairiidriss Restaurant-website-php-mysqlAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried… | |
| Aplazada | Alta (8.5) | 0.36% | — | Motopress Restaurant MenuAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant MenuAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Motopress Restaurant MenuAI | 26/6/2026 | 5/10/2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Wdmtech Vrestaurant | 19/6/2026 | 21/8/2026 | Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint with crafted SQL payloads in the keysearch… |