Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.46%—Oretnom23 Online Eyewear Shop31/3/202517/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
AnalizadaMedia (6.5)0.22%—Shopxo28/3/202517/6/2026
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
AnalizadaMedia (6.3)0.28%—Shopxo28/3/202517/6/2026
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
AnalizadaMedia (6.3)0.28%—Shopxo28/3/202517/6/2026
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
AplazadaAlta (8.1)0.47%—Boggibill Getshop EcommerceAI28/3/202517/6/2026
Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This issue affects GetShop ecommerce: from n/a through <= 1.3.
AplazadaMedia (6.5)0.22%—Cornershop Better Section Navigation WidgetAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cornershop Better Section Navigation Widget better-section-navigation allows Stored XSS.This issue affects Better Section Navigation Widget: from n/a through <= 1.6.1.
AnalizadaMedia (6.9)0.64%—Oretnom23 Online Eyewear Shop27/3/202517/6/2026
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argument ID leads to sql injection. The attack can be initiated…
AplazadaMedia (4.3)0.21%—Xiaomi Shop ApplicationAI27/3/202517/6/2026
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
AplazadaAlta (7.1)0.19%—Wpshop CallphonerAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r callphoner allows Stored XSS.This issue affects CallPhone'r: from n/a through <= 1.1.1.
AplazadaCrítica (9.3)0.25%—Wpshopee Awesome LogosAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpshopee Awesome Logos awesome-logos allows SQL Injection.This issue affects Awesome Logos: from n/a through <= 1.2.
AnalizadaMedia (6.9)0.69%—Oretnom23 Online Eyewear Shop23/3/202517/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed…
AnalizadaMedia (6.5)0.16%—Hikashop15/3/202517/6/2026
A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.
AnalizadaCrítica (9.8)0.68%—Potenzaglobalsolutions Ciyashop14/3/202517/6/2026
The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization of untrusted input in the 'add_ciyashop_wishlist' and 'ciyashop_get_compare' functions. This makes it possible for unauthenticated attackers to inject…
AnalizadaMedia (5.4)0.26%—Hasthemes Shoplentor12/3/202517/6/2026
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash Sale Countdown module in all versions up to, and including, 3.1.0 due to insufficient input…
AnalizadaAlta (7.2)0.44%—Guchengwuyue Yshopmall4/3/202517/6/2026
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
AnalizadaMedia (6.9)0.62%—Code-projects Shopping Portal4/3/202517/6/2026
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (6.9)0.65%—Codezips Online Shopping Website4/3/202517/6/2026
A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AplazadaAlta (8.1)0.48%—Hashshop WizshopAI3/3/202517/6/2026
Path Traversal: '.../...//' vulnerability in hashshop WizShop wizshop allows Path Traversal.This issue affects WizShop: from n/a through <= 3.0.2.
AnalizadaMedia (6.9)0.62%—Codezips Online Shopping Website3/3/202517/6/2026
A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.3)0.52%—Phpgurukul Online Shopping Portal3/3/202517/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /product-details.php. The manipulation of the argument quality/price/value/name/summary/review leads to sql injection. The attack can be launched…
AplazadaMedia (6.1)0.34%—SoteshopAI28/2/202517/6/2026
Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in /app-google-custom-search/searchResults. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform…
AnalizadaCrítica (9.8)0.48%—Shopxo27/2/202517/6/2026
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
AnalizadaBaja (3.4)0.36%—Webdesigner-profi Joomshopping25/2/202517/6/2026
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.
AnalizadaAlta (7.2)0.51%—Hikashop25/2/202517/6/2026
A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.
AnalizadaMedia (5.3)0.44%—Sparkshop24/2/202517/6/2026
An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.