Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.46% | — | Oretnom23 Online Eyewear Shop | 31/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.5) | 0.22% | — | Shopxo | 28/3/2025 | 17/6/2026 | shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places. | |
| Analizada | Media (6.3) | 0.28% | — | Shopxo | 28/3/2025 | 17/6/2026 | ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings. | |
| Analizada | Media (6.3) | 0.28% | — | Shopxo | 28/3/2025 | 17/6/2026 | ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. | |
| Aplazada | Alta (8.1) | 0.47% | — | Boggibill Getshop EcommerceAI | 28/3/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This issue affects GetShop ecommerce: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Cornershop Better Section Navigation WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cornershop Better Section Navigation Widget better-section-navigation allows Stored XSS.This issue affects Better Section Navigation Widget: from n/a through <= 1.6.1. | |
| Analizada | Media (6.9) | 0.64% | — | Oretnom23 Online Eyewear Shop | 27/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argument ID leads to sql injection. The attack can be initiated… | |
| Aplazada | Media (4.3) | 0.21% | — | Xiaomi Shop ApplicationAI | 27/3/2025 | 17/6/2026 | A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpshop CallphonerAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r callphoner allows Stored XSS.This issue affects CallPhone'r: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Wpshopee Awesome LogosAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpshopee Awesome Logos awesome-logos allows SQL Injection.This issue affects Awesome Logos: from n/a through <= 1.2. | |
| Analizada | Media (6.9) | 0.69% | — | Oretnom23 Online Eyewear Shop | 23/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.5) | 0.16% | — | Hikashop | 15/3/2025 | 17/6/2026 | A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions. | |
| Analizada | Crítica (9.8) | 0.68% | — | Potenzaglobalsolutions Ciyashop | 14/3/2025 | 17/6/2026 | The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization of untrusted input in the 'add_ciyashop_wishlist' and 'ciyashop_get_compare' functions. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.4) | 0.26% | — | Hasthemes Shoplentor | 12/3/2025 | 17/6/2026 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash Sale Countdown module in all versions up to, and including, 3.1.0 due to insufficient input… | |
| Analizada | Alta (7.2) | 0.44% | — | Guchengwuyue Yshopmall | 4/3/2025 | 17/6/2026 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. | |
| Analizada | Media (6.9) | 0.62% | — | Code-projects Shopping Portal | 4/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.65% | — | Codezips Online Shopping Website | 4/3/2025 | 17/6/2026 | A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Alta (8.1) | 0.48% | — | Hashshop WizshopAI | 3/3/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in hashshop WizShop wizshop allows Path Traversal.This issue affects WizShop: from n/a through <= 3.0.2. | |
| Analizada | Media (6.9) | 0.62% | — | Codezips Online Shopping Website | 3/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.52% | — | Phpgurukul Online Shopping Portal | 3/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /product-details.php. The manipulation of the argument quality/price/value/name/summary/review leads to sql injection. The attack can be launched… | |
| Aplazada | Media (6.1) | 0.34% | — | SoteshopAI | 28/2/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in /app-google-custom-search/searchResults. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform… | |
| Analizada | Crítica (9.8) | 0.48% | — | Shopxo | 27/2/2025 | 17/6/2026 | ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php. | |
| Analizada | Baja (3.4) | 0.36% | — | Webdesigner-profi Joomshopping | 25/2/2025 | 17/6/2026 | A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend. | |
| Analizada | Alta (7.2) | 0.51% | — | Hikashop | 25/2/2025 | 17/6/2026 | A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend. | |
| Analizada | Media (5.3) | 0.44% | — | Sparkshop | 24/2/2025 | 17/6/2026 | An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. |