Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.59%—Tibco Spotfire AnalystAITibco Spotfire ServerAITibco Spotfire FOR AWS MarketplaceAI27/6/202417/6/2026
Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires human interaction from a person other than…
AplazadaCrítica (9.8)0.46%—JA Module JA MarketplaceAI19/6/202417/6/2026
In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontController::init()` allow…
AplazadaAlta (8.6)0.39%—Multivendorx WC MarketplaceAI11/6/202417/6/2026
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.
AplazadaMedia (6.5)0.36%—Multivendorx WC MarketplaceAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Stored XSS.This issue affects WC Marketplace: from n/a through 4.1.3.
ModificadaMedia (5.4)0.44%—Wclovers Wcfm Marketplace11/1/202417/6/2026
The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
ModificadaCrítica (9.8)0.52%—Softomi Advanced C2C Marketplace Software21/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection. This issue affects Softomi Advanced C2C Marketplace Software: before 12122023.
ModificadaMedia (6.1)0.41%—Softomi Advanced C2C Marketplace Software21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı allows Reflected XSS. This issue affects Softomi Gelişmiş C2C Pazaryeri Yazılımı: before 12122023.
ModificadaAlta (7.2)0.73%—Wcvendors Woocommerce Multi-vendor, Woocommerce Marketplace, Product Vendors19/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Vendors WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors.This issue affects WC Vendors – WooCommerce Multi-Vendor, WooCommerce Marketplace, Product Vendors: from n/a through 2.4.7.
ModificadaMedia (5.4)0.47%—Wclovers Woocommerce Multivendor Marketplace9/6/202317/6/2026
The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'get_item', 'get_order_notes' and 'add_order_note' functions in versions up to, and including, 1.5.3. This makes it possible for…
ModificadaAlta (8.8)0.25%—Wclovers Wcfm Marketplace5/4/202317/6/2026
The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying shipping method details,…
ModificadaAlta (8.8)0.72%—Wclovers Wcfm Marketplace5/4/202317/6/2026
The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a wide…
ModificadaMedia (5.4)0.69%—Wcvendors WC Vendors Marketplace6/2/202317/6/2026
The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.47%—Mongoosemarketplace Mongoose Page Plugin23/1/202317/6/2026
The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (4.3)0.32%—Wc-marketplace Multivendor Marketplace Solution FOR Woocommerce - WC Marketplace5/9/202217/6/2026
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by…
ModificadaMedia (6.5)0.72%—Tibco Data VirtualizationTibco Data Virtualization FOR AWS Marketplace19/7/202217/6/2026
The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with network access to obtain read access to application information on the affected system.…
ModificadaMedia (5.5)0.56%—Tibco Data VirtualizationTibco Data Virtualization FOR AWS Marketplace12/1/202217/6/2026
The Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, and TIBCO Data Virtualization for AWS Marketplace contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to download…
ModificadaMedia (6.5)0.79%—Tibco Data VirtualizationTibco Data Virtualization FOR AWS Marketplace18/8/202017/6/2026
The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains a vulnerability that theoretically allows a malicious authenticated user to download any arbitrary file from the affected system. The user must be authenticated…
ModificadaMedia (4.3)12%💥 ExploitWpmarketplace Project Wpmarketplace6/11/201917/6/2026
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (dot dot) in the file parameter.
ModificadaAlta (8.8)47%💥 ExploitWpmarketplace Project Wpmarketplace6/11/201917/6/2026
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
ModificadaAlta (7.5)1.4%—Wc-marketplace WC Catalog Enquiry27/8/201917/6/2026
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
ModificadaCrítica (9.8)2.3%—Flippa Marketplace Clone Project Flippa Marketplace Clone19/6/201917/6/2026
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
ModificadaMedia (6.1)0.67%—Marketplace Script Project Marketplace Script4/10/201817/6/2026
PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword.
ModificadaMedia (6.1)0.63%—Vanguard Project Marketplace Digital Products PHP28/12/201717/6/2026
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
ModificadaAlta (8.8)0.46%—Vanguard Project Marketplace Digital Products PHP28/12/201717/6/2026
Vanguard Marketplace Digital Products PHP has CSRF via /search.
ModificadaAlta (8.8)6.0%💥 ExploitVanguard Project Marketplace Digital Products PHP27/12/201717/6/2026
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
Orbitaley — Vulnerabilidades