Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.4)——Dell Csi-powerflexAIDell Csi-powermaxAIDell Csi-powerstoreAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
AplazadaMedia (6.9)——Mooncake StoreAI6/10/20266/10/2026
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at…
AplazadaAlta (8.8)——Mooncake StoreAI6/10/20266/10/2026
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects…
AplazadaMedia (6.9)——Mooncake StoreAI6/10/20266/10/2026
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client…
AplazadaAlta (8.8)——Mooncake StoreAI6/10/20266/10/2026
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe…
AplazadaAlta (7.5)0.32%—Museder RestoreoneAI6/10/20266/10/2026
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.
AplazadaAlta (7.1)0.24%—Storegrowth Smart Sales Booster FOR WoocommerceAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.
AplazadaMedia (4.3)0.18%—Inspireui Mstore APIAI2/10/20262/10/2026
The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
AplazadaMedia (5.9)0.30%—WP Store LocatorAI30/9/202630/9/2026
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
Pendiente de análisisAlta (8.1)0.32%—Openstack Glance StoreAI25/9/202630/9/2026
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.
AplazadaMedia (5.5)0.28%—Abdurrab5 Online-makeup-storeAI23/9/202624/9/2026
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.25%—Abdurrab5 Online-makeup-storeAI23/9/202629/9/2026
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published…
AplazadaMedia (5.5)0.25%—Abdurrab5 Online-makeup-storeAI23/9/202624/9/2026
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product…
En análisisAlta (7.2)0.26%—Joomla Easy StoreAI23/9/202623/9/2026
Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core Joomla mail configuration (fromname, mailfrom) in configuration.php without…
En análisisAlta (8.6)0.31%—Joomshaper Easy StoreAI23/9/202623/9/2026
Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-level and asset-level ACL permission checks. Any authenticated backend user could…
En análisisAlta (7.2)0.17%—Joomshaper Easy StoreAI23/9/202623/9/2026
Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers,…
En análisisAlta (8.6)0.28%—Joomshaper Easy StoreAIJoomlaAI23/9/202625/9/2026
Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) took input IDs and directly concatenated them into raw SQL IN (...) clauses in…
En análisisAlta (8.6)0.28%—Joomshaper Easy StoreAI23/9/202625/9/2026
Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) parsed the ids parameter as a comma-separated string and imploded it directly into…
En análisisMedia (5.3)0.17%—Joomshaper Easy StoreAI23/9/202623/9/2026
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addReview) accepted submissions without verifying an anti-CSRF token (the check had been…
En análisisAlta (8.2)0.33%—Joomshaper Easy StoreAI23/9/202623/9/2026
Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email address. The server returned complete shipping details (full name, phone number,…
Pendiente de análisisAlta (8.7)0.57%—Concretecms Community StoreAI22/9/202625/9/2026
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by…
Pendiente de análisisAlta (8.6)0.37%💥 PoCConcrete Community StoreAI18/9/202628/9/2026
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
AplazadaMedia (4.9)0.66%—Store ExporterAI18/9/202618/9/2026
The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above,…
AplazadaAlta (7.5)0.37%—WP Multi Store Locator PROAI18/9/202619/9/2026
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
Pendiente de análisisAlta (8.2)0.27%—Libp2pAILibp2p Peer-storeAI17/9/202624/9/2026
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRecord.peerId in the signed payload to equal the signer peer ID derived by…
Orbitaley — Vulnerabilidades