Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.43% | — | Plainware Locatoraid Store LocatorAI | 7/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in plainware Locatoraid Store Locator locatoraid allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.50. | |
| Aplazada | Media (6.1) | 0.37% | — | Store Credit Gift Cards FOR WoocommerceAI | 7/1/2025 | 17/6/2026 | The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'coupon', 'start_date', and 'end_date' parameters in all versions up to, and including, 1.0.49.46 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (5.3) | 0.51% | — | Code-projects Online Shoe Store | 4/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /summary.php. The manipulation of the argument tid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (6.9) | 0.69% | — | Code-projects Online Shoe Store | 4/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.62% | — | Code-projects Online Shoe Store | 4/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.4) | 0.31% | — | Wpexperts WP Multi Store Locator | 4/1/2025 | 17/6/2026 | The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web… | |
| Analizada | Media (5.3) | 0.53% | — | Code-projects Online Shoe Store | 4/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /details2.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.61% | — | Code-projects Online Shoe Store | 4/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (6.5) | 0.30% | — | Storeapps Putler Connector FOR WoocommerceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Storeplugin ShopelementAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StorePlugin ShopElement shopelement allows Stored XSS.This issue affects ShopElement: from n/a through <= 2.0.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Wpxpo WowstoreAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WPXPO WowStore product-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowStore: from n/a through <= 2.7.8. | |
| Aplazada | Media (4.3) | 0.29% | — | Storeapps Smart Manager FOR WP E CommerceAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0. | |
| Analizada | Media (6.9) | 0.68% | — | 1000projects Bookstore Management System | 29/12/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /order_process.php. The manipulation of the argument fnm leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Alta (8.7) | 0.50% | — | Oppostore IOSAI | 25/12/2024 | 17/6/2026 | In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation. | |
| Analizada | Alta (8.2) | 0.41% | — | Oracle Istore | 24/12/2024 | 17/6/2026 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 0.45% | — | Shopfiles Ebook Store | 21/12/2024 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.1) | 0.37% | — | G WEB PRO Store LocatorAI | 21/12/2024 | 17/6/2026 | The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.36% | — | Shopfiles Ebook Store | 21/12/2024 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.8001. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Aplazada | Crítica (9.8) | 0.93% | — | Lotsoflocales Store LocatorAI | 20/12/2024 | 17/6/2026 | The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code… | |
| Analizada | Alta (7.1) | 0.27% | — | Dell Powerstoreos | 19/12/2024 | 11/9/2026 | Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files. | |
| Aplazada | Alta (7.1) | 0.46% | — | Dotstore Advance Menu ManagerAI | 18/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Menu Manager: from n/a through <= 3.1.1. | |
| Aplazada | Alta (8.7) | 0.70% | — | Oppo Store APPAI | 18/12/2024 | 17/6/2026 | In OPPO Store APP, there's a possible escalation of privilege due to improper input validation. | |
| Analizada | Crítica (9.1) | 0.60% | — | 1000projects Bookstore Management System | 17/12/2024 | 17/6/2026 | A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection. | |
| Aplazada | Alta (7.1) | 0.44% | — | Icdsoft Reseller StoreAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icdsoft ICDSoft Reseller Store icdsoft-reseller-store allows Reflected XSS.This issue affects ICDSoft Reseller Store: from n/a through <= 2.4.5. | |
| Analizada | Media (4.3) | 0.21% | — | Themify Store Locator | 13/12/2024 | 17/6/2026 | The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the setting_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged… |