Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.39% | — | Carmelo Computer Book Store | 14/12/2025 | 7/10/2026 | A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.5) | 0.51% | — | Campcodes Retro Basketball Shoes Online Store | 11/12/2025 | 7/10/2026 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Aplazada | Alta (8.5) | 0.14% | — | Lenovo APP StoreAILenovo BrowserAI | 10/12/2025 | 25/9/2026 | A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions. | |
| Aplazada | Alta (8.5) | 0.30% | — | Agilelogix Store LocatorAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2. | |
| Modificada | Baja (2) | 0.34% | — | Campcodes Retro Basketball Shoes Online Store | 8/12/2025 | 7/10/2026 | A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Alta (7.5) | 0.44% | — | Linuxfoundation Sigstore Timestamp Authority | 4/12/2025 | 17/6/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also… | |
| Analizada | Baja (3.3) | 0.10% | — | Samsung Galaxy Store | 2/12/2025 | 25/9/2026 | Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store. | |
| Aplazada | Alta (7.3) | 0.14% | — | AMD StoremiAI | 23/11/2025 | 26/9/2026 | Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.3) | 0.14% | — | AMD StoremiAI | 23/11/2025 | 26/9/2026 | A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Mstoreapp Mobile APPAIMstoreapp Mobile MultivendorAI | 21/11/2025 | 17/6/2026 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address. | |
| Modificada | Baja (2) | 0.34% | — | Campcodes Retro Basketball Shoes Online Store | 20/11/2025 | 17/6/2026 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and… | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit… | |
| Modificada | Baja (2) | 0.36% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely.… | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Alta (7.5) | 0.45% | — | Oretnom23 Simple Online Book Store System | 14/11/2025 | 5/7/2026 | Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql. | |
| Aplazada | Media (5.5) | 0.35% | — | Dinukanavawatna DEE StoreAI | 12/11/2025 | 17/6/2026 | A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. The attack may be performed from remote. The exploit has been published and may be used. Multiple endpoints are affected. | |
| Analizada | Alta (7) | 0.12% | — | Lenovo APP Store | 12/11/2025 | 17/6/2026 | An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application. | |
| Aplazada | Alta (7.7) | 0.21% | — | Lenovo PC ManagerAILenovo APP StoreAILenovo BrowserAILenovo Legion ZoneAI | 12/11/2025 | 17/6/2026 | A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code. | |
| Aplazada | Alta (8.8) | 0.37% | — | Nvidia AistoreAI | 11/11/2025 | 17/6/2026 | NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (5.3) | 0.86% | — | Nvidia AistoreAI | 11/11/2025 | 17/6/2026 | NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure. A successful exploit of this vulnerability may lead to information disclosure. | |
| Analizada | Media (6.5) | 0.32% | 💥 PoC | Keruistore Kerui K259 Firmware | 10/11/2025 | 17/6/2026 | KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root. | |
| Analizada | Media (6.1) | 0.21% | — | Nooncarlett Techstore | 7/11/2025 | 17/6/2026 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter. | |
| Analizada | Media (6.1) | 0.21% | — | Nooncarlett Techstore | 7/11/2025 | 17/6/2026 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter. | |
| Analizada | Alta (8.6) | 85% | ⚠ Explotación activa💥 Exploit | Sangoma Filestore | 7/11/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection ->… | |
| Aplazada | Alta (7.5) | 0.46% | — | Josh Kohlbach Woocommerce Store ToolkitAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach WooCommerce Store Toolkit woocommerce-store-toolkit allows PHP Local File Inclusion.This issue affects WooCommerce Store Toolkit: from n/a through <= 2.4.3. |