Vulnerabilities in Restaurant Brands International

10 results
Vexday analysis

Restaurant Brands International apresenta 10 vulnerabilidades catalogadas, com apenas 1 crítica, mas nenhuma sob exploração ativa conhecida, o que reduz o risco imediato. A ausência de divulgações recentes (últimos 90 dias) indica que a superfície de ataque não está em expansão acidental. A fraqueza dominante em controle de acesso (CWE-863) aponta para possíveis falhas em autorização, exigindo revisão de mecanismos de permissão, particularmente em sistemas operacionais ou aplicações de gestão.

CVE-2025-62645CRITICALThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token witEPSS 0.7%CVE-2025-62646MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of converEPSS 0.5%CVE-2025-62649MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipEPSS 0.5%CVE-2025-62650HIGHThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostEPSS 0.5%CVE-2025-62642MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does notEPSS 0.5%CVE-2025-62644MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal informatioEPSS 0.4%CVE-2025-62648MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio vEPSS 0.4%CVE-2025-62651MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating inEPSS 0.4%CVE-2025-62647MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be usEPSS 0.4%CVE-2025-62643LOWThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail mesEPSS 0.3%