Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.33% | — | Fabian Mobile Shop Management System | 3/9/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.56% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.53% | — | Janobe Bakeshop Online Ordering System | 29/8/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made… | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.4) | 0.27% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary… | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions. | |
| Analizada | Crítica (9.8) | 0.78% | — | Sparkshop | 25/8/2025 | 17/6/2026 | Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component | |
| Analizada | Alta (8.1) | 0.22% | — | Shopizer | 22/8/2025 | 17/6/2026 | An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. This allows any malicious origin to make authenticated… | |
| Analizada | Alta (8.8) | 0.24% | — | Old-peanut Open-shop | 20/8/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Dts-shopAI | 20/8/2025 | 17/6/2026 | Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index. | |
| Analizada | Media (6.1) | 0.22% | — | Shopfiles Ebook Store | 16/8/2025 | 17/6/2026 | The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers. | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (4.3) | 0.13% | — | Shopfiles Ebook StoreAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.This issue affects Ebook Store: from n/a through <= 5.8013. | |
| Aplazada | Alta (7.1) | 0.23% | — | Zoomit Woocommerce Shop Page BuilderAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce Shop Page Builder allows Reflected XSS. This issue affects WooCommerce Shop Page Builder: from n/a through 2.27.7. | |
| Analizada | Media (6.1) | 0.22% | — | Fahadmahmood External Store FOR Shopify | 14/8/2025 | 17/6/2026 | The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (7.8) | 0.24% | — | Adobe Photoshop | 12/8/2025 | 17/6/2026 | Photoshop Desktop versions 25.12.3, 26.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (6) | 0.39% | — | Shopware | 6/8/2025 | 17/6/2026 | A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations. | |
| Analizada | Media (6.1) | 0.38% | — | Shopware | 5/8/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, allowing an attacker to inject malicious JavaScript. This… | |
| Aplazada | Baja (1.9) | 0.13% | — | TVB BIG BIG ShopAI | 3/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component hk.com.tvb.bigbigshop. The manipulation leads to improper export of android application components. An attack has to… | |
| Aplazada | Baja (2) | 0.27% | — | Wx-shopAI | 3/8/2025 | 17/6/2026 | A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This issue affects some unknown processing of the file /user/editUI. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2.1) | 0.21% | — | Wx-shopAI | 3/8/2025 | 17/6/2026 | A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… |