Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.40%—Liquidthemes LogisticshubAI4/7/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a Web Shell to a Web Server.This issue affects LogisticsHub: from n/a through <= 1.1.6.
AnalizadaCrítica (9.3)0.51%—Scshr HR Portal6/6/202517/6/2026
A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.
AnalizadaAlta (8.8)0.37%—Scshr HR Portal6/6/202517/6/2026
A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.
AnalizadaAlta (8.8)0.39%—Scshr HR Portal6/6/202517/6/2026
An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary file paths.
AnalizadaCrítica (9.9)0.52%—Scshr HR Portal6/6/202517/6/2026
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.
AnalizadaAlta (8.7)0.45%—Scshr HR Portal6/6/202517/6/2026
An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to obtain partial files by specifying arbitrary file paths.
AnalizadaCrítica (9.9)0.54%—Scshr HR Portal6/6/202517/6/2026
A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.
AnalizadaMedia (4.3)0.42%—Creativewerkdesigns Wpsyncsheets12/2/202517/6/2026
The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsslwp_reset_settings() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.7)0.37%—Messagepack-csharpAI17/10/202417/6/2026
### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by an attacker that sends data contrived to produce hash collisions, leading to large CPU consumption disproportionate to the size of the data being deserialized. This is similar…
AnalizadaMedia (5.4)0.27%—Shopex Ecshop22/5/202417/6/2026
Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.
AplazadaAlta (7.5)0.59%—EcshopAI4/4/202417/6/2026
SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.
AnalizadaMedia (4.2)0.28%—Kirillmakarov Musicshelf11/3/202417/6/2026
A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the component SHA-1 Handler. The manipulation leads to password hash with insufficient…
AnalizadaMedia (4.6)0.33%—Kirillmakarov Musicshelf10/3/202417/6/2026
A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup Handler. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to launch the attack on the…
ModificadaAlta (8.8)0.59%—Shopex Ecshop15/2/202417/6/2026
A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.96%—Csharp CWS Collaborative Development Platform15/12/202317/6/2026
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
ModificadaAlta (8.8)0.69%—Csharp CWS Collaborative Development Platform15/12/202317/6/2026
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in…
ModificadaMedia (6.5)0.55%—Csharp CWS Collaborative Development Platform15/12/202317/6/2026
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive…
ModificadaAlta (8.8)0.66%—Shopex Ecshop29/9/202317/6/2026
A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (6.5)0.53%—Shopex Ecshop29/9/202317/6/2026
A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (7.8)0.18%—Scshr HR Portal7/9/202317/6/2026
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use…
ModificadaMedia (6.5)0.70%—Shopex Ecshop4/8/202317/6/2026
ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
ModificadaAlta (8.8)0.75%—Shopex Ecshop6/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (8.8)0.75%—Shopex Ecshop6/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has…
ModificadaCrítica (9.8)0.88%—Shopex Ecshop11/2/202317/6/2026
A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.50%—Clicshopping V35/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.
Orbitaley — Vulnerabilidades