Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.48%—Implecode Product Catalog Simple29/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue affects Product Catalog Simple: from n/a through 1.7.6.
ModificadaMedia (6.1)0.53%—Multivendorx Product Catalog Mode FOR Woocommerce18/12/202317/6/2026
The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
ModificadaAlta (8.8)0.25%—Pixelyoursite Product Catalog Feed17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
ModificadaMedia (6.5)0.28%—Implecode Ecommerce Product Catalog4/12/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products
ModificadaMedia (5.4)0.41%—Implecode Ecommerce Product Catalog23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.26 versions.
ModificadaCrítica (9.8)0.98%—Myprestamodules Product Catalog (csv, Excel) Import20/9/202317/6/2026
SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.
ModificadaAlta (7.5)32%💥 ExploitMyprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts20/9/202317/6/2026
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
ModificadaMedia (6.1)0.46%—Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio31/7/202317/6/2026
The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (4.3)0.48%—Implecode Ecommerce Product Catalog1/7/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save manual digital orders…
ModificadaMedia (4.3)0.48%—Implecode Ecommerce Product Catalog1/7/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save…
ModificadaMedia (4.3)0.38%—Implecode Product Catalog Simple1/7/202317/6/2026
The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to update product meta via a…
ModificadaMedia (4.8)0.50%—Etoilewebdesign Ultimate Product Catalog27/6/202317/6/2026
The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.46%—Pixelyoursite Product Catalog Feed2/5/202317/6/2026
The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.52%—Pixelyoursite Product Catalog Feed2/5/202317/6/2026
The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
ModificadaMedia (6.1)0.38%—Implecode Product Catalog Simple7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions.
ModificadaMedia (4.8)0.39%—Implecode Ecommerce Product Catalog7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.4 versions.
ModificadaMedia (4.8)0.38%—Implecode Ecommerce Product Catalog17/3/202317/6/2026
The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaMedia (5.4)0.60%—Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio11/4/202217/6/2026
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform…
ModificadaMedia (6.5)0.47%—Etoilewebdesign Ultimate Product Catalog7/2/202217/6/2026
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example
ModificadaMedia (6.1)1.7%💥 ExploitImplecode Ecommerce Product Catalog23/11/202117/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)0.92%—Etoilewebdesign Ultimate Product Catalog2/8/201717/6/2026
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.
ModificadaCrítica (9.8)1.8%—Etoilewebdesign Ultimate Product Catalog2/8/201717/6/2026
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item,…
ModificadaMedia (5.4)0.27%—Shaklee Product Catalog Project Shaklee Product Catalog19/10/201417/6/2026
The Shaklee Product Catalog (aka com.wProductCatalog) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.1%💥 ExploitHumayun Shabbir Bhutta ASP Product Catalog24/7/200916/6/2026
SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.
ModificadaMedia (5)2.3%💥 ExploitHumayun Shabbir Bhutta ASP Product Catalog17/4/200916/6/2026
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.
Orbitaley — Vulnerabilidades