Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.48%—Code-projects Online Shoe Store20/6/202517/6/2026
A vulnerability was found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /cart.php. The manipulation of the argument qty[] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.5)0.48%—Code-projects Online Shoe Store20/6/202517/6/2026
A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus1.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
AplazadaMedia (5.9)0.20%—Shopfiles Ebook StoreAI17/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows Stored XSS.This issue affects Ebook Store: from n/a through <= 5.8008.
AplazadaMedia (6.6)0.27%—Agilelogix Agile Store LocatorAI6/6/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2.
AplazadaAlta (7.6)0.35%—Agilelogix Store LocatorAI6/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.5.1.
AplazadaAlta (7.5)0.74%—PHPAIFahadmahmood External Store FOR ShopifyAI6/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fahad Mahmood External Store for Shopify wp-shopify allows PHP Local File Inclusion.This issue affects External Store for Shopify: from n/a through <= 1.5.9.
AplazadaMedia (4.3)0.16%—Storepro Subscription Renewal Reminders FOR WoocommerceAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce subscriptions-renewal-reminders allows Cross Site Request Forgery.This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through <= 1.4.1.
AnalizadaAlta (7.5)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaMedia (5.9)1.2%—HPE Storeonce System2/6/202517/6/2026
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
AnalizadaCrítica (9.1)0.86%—HPE Storeonce System2/6/202517/6/2026
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
AnalizadaCrítica (9.8)1.1%—HPE Storeonce System2/6/202517/6/2026
An authentication bypass vulnerability exists in HPE StoreOnce Software.
AnalizadaAlta (7.5)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaCrítica (9.8)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaMedia (6.9)0.62%—HPE Storeonce System2/6/202517/6/2026
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
AnalizadaAlta (7.5)1.2%—HPE Storeonce System2/6/202517/6/2026
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
AnalizadaMedia (6.5)0.31%—Dell Powerstoreos28/5/202511/9/2026
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded…
AplazadaMedia (5.1)0.51%—Real Easy StoreAI28/5/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This vulnerability can be exploited to steal sensitive user data,…
AnalizadaMedia (4.8)0.31%—Razormist Simple Computer Store System28/5/202517/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer overflow. An attack has to be approached locally. The exploit…
AnalizadaMedia (4.3)0.29%—Inspireui Mstore API27/5/202517/6/2026
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level…
ModificadaCrítica (9.8)1.4%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
ModificadaCrítica (9.1)1.4%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,…
ModificadaAlta (7.5)0.68%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
ModificadaCrítica (9.8)1.3%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
AplazadaCrítica (10)0.44%—Storekeeper B.V Storekeeper FOR WoocommerceAI23/5/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4.
AplazadaCrítica (9.3)0.35%—Superstorefinder Super Store FinderAI19/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp allows SQL Injection.This issue affects Super Store Finder: from n/a through <= 7.2.