Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.27% | — | Sunshinephotocart Sunshine Photo Cart | 28/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. | |
| Modificada | Media (6.1) | 0.62% | — | Sunshinephotocart Sunshine Photo Cart | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.5. | |
| Analizada | Media (5.3) | 0.34% | — | Lizardbyte Sunshine | 10/9/2024 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing authentication due to a PIN validation error. The pairing attempt fails due to the incorrect PIN, but the certificate… | |
| Analizada | Baja (2.9) | 0.22% | — | Lizardbyte Sunshine | 16/5/2024 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named `C:\Program.exe`, `C:\Program.bat`, or `C:\Program.cmd` on the user's computer. This attack vector… | |
| Analizada | Media (5.9) | 0.51% | — | Lizardbyte Sunshine | 8/4/2024 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a… | |
| Analizada | Alta (7.3) | 0.49% | — | Lizardbyte Sunshine | 5/4/2024 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without authentication due to a path traversal vulnerability. Users who exposed the Sunshine configuration web user interface outside of localhost… | |
| Modificada | Crítica (9.8) | 0.46% | — | Sunshinephotocart Sunshine Photo Cart | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. | |
| Modificada | Media (6.1) | 0.72% | — | Sunshinephotocart Sunshine Photo Cart | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. | |
| Modificada | Media (5.3) | 0.68% | — | Sunshinephotocart Sunshine Photo Cart | 29/2/2024 | 17/6/2026 | The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical… | |
| Modificada | Media (6.5) | 0.42% | — | Sunshinephotocart Sunshine Photo Cart | 20/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0. | |
| Modificada | Media (4.3) | 0.38% | — | Sunshinephotocart Sunshine Photo Cart | 12/7/2023 | 17/6/2026 | The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function. This makes it possible for unauthenticated attackers to save custom post data via a… | |
| Modificada | Alta (8.8) | 0.26% | — | Sunshinephotocart Sunshine Photo Cart | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions. | |
| Modificada | Media (6.1) | 0.90% | — | Sunshinephotocart Sunshine Photo Cart | 9/1/2023 | 17/6/2026 | The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. |