Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

1166 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.29%—Rest API LOGAI1/10/20261/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
AplazadaAlta (7.1)0.16%—Five Star Restaurant ReviewsAI1/10/20261/10/2026
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in…
AplazadaAlta (8.7)0.44%—RestbedAI30/9/20261/10/2026
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through…
AplazadaAlta (8.7)0.55%—RestbedAI30/9/202630/9/2026
restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory…
AplazadaBaja (2.1)0.37%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed…
AplazadaMedia (5.5)0.33%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The…
AplazadaMedia (5.5)0.41%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be…
AplazadaMedia (5.5)0.41%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be…
AplazadaMedia (5.5)0.41%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The…
AplazadaAlta (8.8)0.28%—Wpeverest ALL IN ONE Files UploadAI30/9/202630/9/2026
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim…
AplazadaAlta (7.2)0.24%—Restaurant Menu AND Food OrderingAI25/9/202625/9/2026
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
Pendiente de análisisAlta (8.7)0.38%—PleskAIPlesk Restful APIAI23/9/202624/9/2026
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.
AplazadaBaja (2.1)0.24%—Adithyayelloju Restaurant Management SystemAI22/9/202623/9/2026
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search Form. This manipulation of the argument s1 causes sql injection. The attack can be…
AplazadaMedia (5.3)0.32%—Magnigenie RestropressAI21/9/202621/9/2026
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
AplazadaBaja (2.1)0.32%—Adithyayelloju Restaurant Management SystemAI20/9/202622/9/2026
A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The manipulation of the argument table/members/price results in sql injection. It is possible to launch the attack remotely.…
AplazadaBaja (2.1)0.33%—Adithyayelloju Restaurant-management-systemAI20/9/202621/9/2026
A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate…
Pendiente de análisisAlta (7.5)0.79%—Redhat ResteasyAI18/9/202618/9/2026
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation,…
Pendiente de análisisAlta (7.4)0.47%—Redhat ResteasyAI18/9/202619/9/2026
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed…
AplazadaMedia (6.5)0.27%—Magnigenie RestropressAI18/9/202618/9/2026
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
AplazadaMedia (5.3)0.34%—Prestashop BlockwishlistAI16/9/202622/9/2026
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'…
AplazadaMedia (5.3)0.34%—Prestashop PsgdprAI16/9/202622/9/2026
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
AplazadaAlta (8.4)0.62%—Zope RestrictedpythonAI16/9/202616/9/2026
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter…
Pendiente de análisisMedia (5.1)0.25%—Arista EOSAIOpenconfig GnmiAIOpenconfig GnsiAIOpenconfig RestconfAI+116/9/202616/9/2026
On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming…
AplazadaMedia (6.9)0.38%—Miniorange JWT Authentication FOR WP Rest ApisAI15/9/202624/9/2026
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification.…