Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Thememove EdumallAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions. | |
| Aplazada | Baja (2.1) | 0.23% | — | Newbee-ltd Newbee-mallAI | 6/10/2026 | 6/10/2026 | A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be… | |
| Aplazada | Baja (2.1) | 0.22% | — | Pickmall LilishopAI | 6/10/2026 | 6/10/2026 | A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.28% | — | Pickmall LilishopAI | 6/10/2026 | 6/10/2026 | A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Alta (7.5) | 0.24% | — | UnimallAI | 5/10/2026 | 6/10/2026 | Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code. | |
| Aplazada | Baja (2.9) | 0.40% | — | Linlinjava LitemallAI | 5/10/2026 | 6/10/2026 | A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.… | |
| Aplazada | Media (5.5) | 0.28% | — | Realjerrytang TacomallAI | 29/9/2026 | 2/10/2026 | A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.3) | 0.18% | — | Mall4jAI | 28/9/2026 | 30/9/2026 | mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling… | |
| Aplazada | Baja (2.1) | 0.16% | — | Mall4jAI | 28/9/2026 | 30/9/2026 | mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the… | |
| Aplazada | Alta (7.1) | 0.24% | — | Mall4jAI | 28/9/2026 | 1/10/2026 | mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information. | |
| Aplazada | Media (5.3) | 0.18% | — | Mall4jAI | 28/9/2026 | 30/9/2026 | mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize… | |
| Aplazada | Media (6.3) | 0.27% | — | Mall4jAI | 28/9/2026 | 30/9/2026 | mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for… | |
| Aplazada | Media (6.9) | 0.29% | — | Mall4jAI | 28/9/2026 | 30/9/2026 | mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Mall4jAI | 28/9/2026 | 1/10/2026 | mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and… | |
| Pendiente de análisis | Alta (7.5) | 0.49% | — | Smallrye Fault ToleranceAIQuarkusAI | 21/9/2026 | 25/9/2026 | A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request.… | |
| Aplazada | Baja (2) | 0.41% | — | Newbee-ltd Newbee-mallAI | 20/9/2026 | 24/9/2026 | A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argument goodsName results in cross site scripting. The attack may be initiated remotely.… | |
| Pendiente de análisis | Media (5.3) | 0.58% | — | Smallrye JWTAI | 17/9/2026 | 21/9/2026 | A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an… | |
| Aplazada | Media (5.3) | 0.49% | — | Kagisearch SmallwebAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be… | |
| Aplazada | Baja (2.9) | 0.48% | — | Phpgurukul Small CRMAI | 13/9/2026 | 16/9/2026 | A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is… | |
| Aplazada | Media (5.3) | 0.47% | — | Exrick XmallAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the… | |
| Aplazada | Media (4.8) | 0.37% | — | Linlinjava LitemallAI | 13/9/2026 | 16/9/2026 | A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack… | |
| Aplazada | Media (4.8) | 0.37% | — | Linlinjava LitemallAI | 13/9/2026 | 14/9/2026 | A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely.… | |
| Aplazada | Media (6.1) | 0.25% | — | Guchengwuyue YshopmallAI | 9/9/2026 | 14/9/2026 | yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files. | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Smallrye GraphqlAI | 31/8/2026 | 1/9/2026 | A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely… | |
| Aplazada | Baja (2.1) | 0.44% | — | Macrozheng MallAI | 29/8/2026 | 1/9/2026 | A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The… |