Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.26% | — | Shobdullar ShopengineAI | 15/9/2026 | 15/9/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input… | |
| Aplazada | Media (5.5) | 0.41% | — | Shopex EcshopAI | 31/8/2026 | 1/9/2026 | A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Media (5.5) | 0.47% | — | Shopex EcshopAI | 31/8/2026 | 1/9/2026 | A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could… | |
| Aplazada | Alta (7.2) | 0.58% | — | ShopengineAI | 25/8/2026 | 28/9/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no… | |
| Aplazada | Media (5.4) | 0.14% | — | ShopengineAI | 13/8/2026 | 26/8/2026 | The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and… | |
| Aplazada | Alta (8.1) | 0.48% | — | Themerex HopeAI | 7/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0. | |
| Aplazada | Alta (8.1) | 0.53% | — | Ancorahemes Faith HopeAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Faith & Hope faith-hope allows PHP Local File Inclusion.This issue affects Faith & Hope: from n/a through <= 2.13.0. | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancoratemes ChildhopeAI | 18/12/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ChildHope childhope allows PHP Local File Inclusion.This issue affects ChildHope: from n/a through <= 1.1.8. | |
| Aplazada | Media (4.3) | 0.12% | — | ShopengineAI | 3/12/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This makes… | |
| Aplazada | Baja (2.7) | 0.22% | — | Shapeshift Shopengine Elementor Woocommerce Builder AddonAI | 25/10/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it… | |
| Aplazada | Baja (2.7) | 0.22% | — | Shopengine Elementor Woocommerce Builder AddonAI | 26/9/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.1) | 0.41% | — | Java-aodeng Hope-bootAI | 24/6/2025 | 17/6/2026 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the component Login. The manipulation of the argument redirect_url leads to open redirect. It is possible to launch the… | |
| Analizada | Baja (2) | 0.45% | — | Java-aodeng Hope-boot | 24/6/2025 | 17/6/2026 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.53% | — | Java-aodeng Hope-boot | 5/5/2025 | 17/6/2026 | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request. | |
| Aplazada | Alta (7.1) | 0.24% | — | Wpshopee Awesome LogosAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos awesome-logos allows Reflected XSS.This issue affects Awesome Logos: from n/a through <= 1.2. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Wpshopee Awesome LogosAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpshopee Awesome Logos awesome-logos allows SQL Injection.This issue affects Awesome Logos: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.25% | — | Storeplugin ShopelementAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StorePlugin ShopElement shopelement allows Stored XSS.This issue affects ShopElement: from n/a through <= 2.0.0. | |
| Aplazada | Crítica (9.1) | 0.36% | — | Hopetree Izone LTS C011b48AI | 8/11/2024 | 17/6/2026 | hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py does not securely filter user input through push_urls() and get_urls(). | |
| Aplazada | Media (5.4) | 0.22% | — | Hopetree Izone LTSAI | 8/11/2024 | 17/6/2026 | hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates. | |
| Analizada | Media (5.4) | 0.27% | — | Shopex Ecshop | 22/5/2024 | 17/6/2026 | Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php. | |
| Modificada | Alta (8.8) | 0.59% | — | Shopex Ecshop | 15/2/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (8.8) | 0.66% | — | Shopex Ecshop | 29/9/2023 | 17/6/2026 | A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (6.5) | 0.53% | — | Shopex Ecshop | 29/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (6.5) | 0.70% | — | Shopex Ecshop | 4/8/2023 | 17/6/2026 | ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel. | |
| Modificada | Crítica (9.8) | 0.19% | — | Hopechart Hqt401 Firmware | 1/6/2023 | 17/6/2026 | Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected too. Multiple vulnerabilities were identified: - The MQTT backend does not require… |