Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.29% | — | Macrozheng MallAI | 29/8/2026 | 31/8/2026 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The… | |
| Aplazada | Media (5.3) | 0.39% | — | Macrozheng MallAI | 25/8/2026 | 27/8/2026 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub… | |
| Aplazada | Media (6.3) | 0.33% | — | Meshtastic MallaAI | 21/8/2026 | 9/9/2026 | Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can… | |
| Aplazada | Baja (2.9) | 0.44% | — | Macrozheng MallAI | 9/8/2026 | 13/8/2026 | A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated… | |
| Aplazada | Media (4.3) | 0.33% | — | Thememove EdumallAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduMall: from n/a through <= 4.5.1. | |
| Aplazada | Baja (2.1) | 0.41% | — | Macrozheng MallAI | 9/7/2026 | 9/7/2026 | A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly… | |
| Aplazada | Alta (8.1) | 0.44% | — | EmallshopAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. | |
| Aplazada | Alta (8.8) | 0.48% | — | Pixel Makers Creative Entrepreneur Booking FOR Small BusinessesAI | 17/6/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5. | |
| Aplazada | Media (5.1) | 0.22% | — | Macrozheng MallAI | 29/5/2026 | 21/7/2026 | A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor deleted the GitHub issue for this… | |
| Aplazada | Media (5.3) | 0.40% | — | UZY Ssm-mallAI | 27/5/2026 | 17/6/2026 | SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components | |
| Aplazada | Alta (7.3) | 0.16% | — | SmallbitvecAI | 26/5/2026 | 24/7/2026 | smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring unsafe… | |
| Aplazada | Baja (2) | 0.41% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to… | |
| Aplazada | Baja (2) | 0.33% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple… | |
| Aplazada | Media (5.5) | 0.41% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exploitation of the… | |
| Analizada | Baja (3.7) | 0.28% | — | Smallstep Step-ca | 10/4/2026 | 17/6/2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device… | |
| Analizada | Alta (8.8) | 0.40% | — | Phpscriptsmall Advance Gift Shop PRO Script | 5/4/2026 | 24/7/2026 | Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database… | |
| Analizada | Alta (8.8) | 0.46% | — | Phpscriptsmall ASK Expert Script | 5/4/2026 | 24/7/2026 | Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in… | |
| Analizada | Alta (8.8) | 0.40% | — | Phpscriptsmall News Website Script | 5/4/2026 | 24/7/2026 | News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information. | |
| Analizada | Alta (8.5) | 0.15% | — | Smallsrv Small Http Server | 26/3/2026 | 17/6/2026 | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing… | |
| Analizada | Alta (8.7) | 0.61% | — | Smallsrv Small Http Server | 26/3/2026 | 17/6/2026 | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server. | |
| Analizada | Crítica (10) | 0.31% | — | Smallstep Step-ca | 19/3/2026 | 17/6/2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0. | |
| Analizada | Alta (8.8) | 0.37% | — | Netartmedia PHP Mall | 12/3/2026 | 17/6/2026 | Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract… | |
| Analizada | Alta (8.8) | 0.36% | — | Netartmedia PHP Mall | 12/3/2026 | 17/6/2026 | Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various parameters. Attackers can craft malicious requests with SQL payloads to extract sensitive database information including user credentials… | |
| Analizada | Baja (2.1) | 0.54% | — | Youlai-mall | 27/2/2026 | 17/6/2026 | A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuController.java of the component App-side Product Pagination Endpoint. Performing a manipulation of the argument… | |
| Analizada | Media (5.1) | 0.22% | — | Phpscriptsmall Fiverr Clone Script | 20/2/2026 | 17/6/2026 | Fiverr Clone Script 1.2.2 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft URLs with script tags in the keyword parameter of search-results.php to execute arbitrary JavaScript in users' browsers. |