Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.38% | — | Xingfuggz BaykeshopAI | 23/2/2026 | 17/6/2026 | A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of the component Article Sidebar Module. Such manipulation of the argument sidebar.content leads to cross site scripting. The… | |
| Aplazada | Media (5.1) | 0.44% | — | SoteshopAI | 23/2/2026 | 17/6/2026 | Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user… | |
| Aplazada | Alta (8.8) | 0.27% | — | Ashop Shopping Cart SoftwareAI | 22/2/2026 | 17/6/2026 | Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract… | |
| Analizada | Media (5.5) | 0.59% | — | Adonesevangelista Agri-trading Online Shopping System | 21/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Product results in sql injection. The attack may be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.69% | — | Edubusinesssolutions Print Shop PRO Webdesk | 20/2/2026 | 17/6/2026 | An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID parameter. | |
| Aplazada | Alta (7.5) | 0.28% | — | Mikado-themes Pawfriends - PET Shop AND Veterinary Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3. | |
| Aplazada | Alta (7.5) | 0.35% | — | Wpshop WP ShopAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.This issue affects WP shop: from n/a through <= 2.6.1. | |
| Aplazada | Alta (8.1) | 0.53% | — | Fuelthemes PeakshopsAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes PeakShops peakshops allows PHP Local File Inclusion.This issue affects PeakShops: from n/a through < 1.5.9. | |
| Aplazada | Alta (8.8) | 0.49% | — | Fuelthemes PeakshopsAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5.9. | |
| Aplazada | Media (5.3) | 0.24% | — | Peregrinethemes ShopwellAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11. | |
| Aplazada | Media (4.3) | 0.33% | — | ShopireAI | 19/2/2026 | 17/6/2026 | The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the shopire_admin_install_plugin() function in all versions up to, and including, 1.0.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the… | |
| Aplazada | Alta (8.6) | 0.69% | — | Hasthemes ShoplentorAI | 18/2/2026 | 17/6/2026 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title', 'wlmessage', and 'wlemail' parameters in the… | |
| Aplazada | Crítica (9.8) | 0.38% | — | PrestashopAIAdvancedpopupcreatorAI | 13/2/2026 | 17/6/2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized… | |
| Analizada | Crítica (9.3) | 0.53% | 💥 PoC | Evershop | 10/2/2026 | 17/6/2026 | EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path values—derived from the url_key stored in the database—into SQL statements via string concatenation and passes them to execute(). As a result, if a malicious string is… | |
| Analizada | Media (6.9) | 0.55% | — | Friendsofshopware Froshadminer | 9/2/2026 | 17/6/2026 | FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users. This vulnerability… | |
| Analizada | Alta (7.5) | 0.55% | — | Bishopfox Sliver | 9/2/2026 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored without a… | |
| Analizada | Baja (2.1) | 0.34% | — | Guchengwuyue Yshopmall | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Analizada | Media (6.5) | 0.56% | — | Bishopfox Sliver | 6/2/2026 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose… | |
| Analizada | Media (5.3) | 0.54% | — | Prestashop | 6/2/2026 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.… | |
| Aplazada | Alta (8.8) | 0.46% | — | Oxid EshopAI | 3/2/2026 | 17/6/2026 | OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through… | |
| Aplazada | Media (5.1) | 0.34% | — | Easycart Easy Cart Shopping CartAI | 1/2/2026 | 17/6/2026 | Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content. | |
| Aplazada | Alta (7.5) | 1.5% | 💥 Exploit | VidshopAI | 28/1/2026 | 17/6/2026 | The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Crítica (9.8) | 0.47% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters. | |
| Analizada | Crítica (9.8) | 0.51% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. | |
| Analizada | Crítica (9.8) | 0.51% | — | Fabian Mobile Shop Management System | 27/1/2026 | 17/6/2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. |