Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.48% | — | Code-projects Online Shoe Store | 20/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /cart.php. The manipulation of the argument qty[] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.48% | — | Code-projects Online Shoe Store | 20/6/2025 | 17/6/2026 | A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus1.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.9) | 0.20% | — | Shopfiles Ebook StoreAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows Stored XSS.This issue affects Ebook Store: from n/a through <= 5.8008. | |
| Aplazada | Media (6.6) | 0.27% | — | Agilelogix Agile Store LocatorAI | 6/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.6) | 0.35% | — | Agilelogix Store LocatorAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.5) | 0.74% | — | PHPAIFahadmahmood External Store FOR ShopifyAI | 6/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fahad Mahmood External Store for Shopify wp-shopify allows PHP Local File Inclusion.This issue affects External Store for Shopify: from n/a through <= 1.5.9. | |
| Aplazada | Media (4.3) | 0.16% | — | Storepro Subscription Renewal Reminders FOR WoocommerceAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce subscriptions-renewal-reminders allows Cross Site Request Forgery.This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through <= 1.4.1. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Media (5.9) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.1) | 0.86% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.8) | 1.1% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Crítica (9.8) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Media (6.9) | 0.62% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Alta (7.5) | 1.2% | — | HPE Storeonce System | 2/6/2025 | 17/6/2026 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | |
| Analizada | Media (6.5) | 0.31% | — | Dell Powerstoreos | 28/5/2025 | 11/9/2026 | Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded… | |
| Aplazada | Media (5.1) | 0.51% | — | Real Easy StoreAI | 28/5/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This vulnerability can be exploited to steal sensitive user data,… | |
| Analizada | Media (4.8) | 0.31% | — | Razormist Simple Computer Store System | 28/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer overflow. An attack has to be approached locally. The exploit… | |
| Analizada | Media (4.3) | 0.29% | — | Inspireui Mstore API | 27/5/2025 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Modificada | Crítica (9.8) | 1.4% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Modificada | Crítica (9.1) | 1.4% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Modificada | Alta (7.5) | 0.68% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Modificada | Crítica (9.8) | 1.3% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Crítica (10) | 0.44% | — | Storekeeper B.V Storekeeper FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Superstorefinder Super Store FinderAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp allows SQL Injection.This issue affects Super Store Finder: from n/a through <= 7.2. |