Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | JON Bishop WP About AuthorAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Bishop WP About Author wp-about-author allows DOM-Based XSS.This issue affects WP About Author: from n/a through <= 1.5. | |
| Analizada | Media (5.1) | 0.57% | — | Shopxo | 24/2/2025 | 17/6/2026 | A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.3) | 0.42% | — | Phpgurukul Online Shopping Portal | 23/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument Product leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.63% | — | Bishopfox Sliver | 19/2/2025 | 17/6/2026 | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed… | |
| Analizada | Media (4.3) | 0.18% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 18/2/2025 | 17/6/2026 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send… | |
| Analizada | Alta (8.8) | 0.25% | — | Shopwarden | 18/2/2025 | 17/6/2026 | The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. This is due to missing or incorrect nonce validation on the save_setting() function. This makes it possible for unauthenticated attackers to update… | |
| Analizada | Alta (8.8) | 0.76% | — | Phpgurukul Online Shopping Portal Project | 14/2/2025 | 17/6/2026 | A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter. | |
| Aplazada | Media (4.8) | 0.27% | — | PrestashopAI | 12/2/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie… | |
| Analizada | Media (5.5) | 0.31% | — | Adobe Photoshop Elements | 11/2/2025 | 17/6/2026 | Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Modificada | Alta (8.8) | 0.70% | — | Fabian Shopping Portal | 6/2/2025 | 17/6/2026 | In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability. | |
| Aplazada | Media (6.1) | 0.16% | — | ShopsiteAI | 4/2/2025 | 17/6/2026 | The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request… | |
| Aplazada | Media (6.4) | 0.25% | — | Brodos Onlineshop PluginAI | 25/1/2025 | 17/6/2026 | The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'BrodosCategory' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.7) | 0.47% | — | InnoshopAI | 24/1/2025 | 17/6/2026 | InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload. | |
| Aplazada | Media (6.2) | 0.41% | — | Prestashop PS ContactinfoAI | 22/1/2025 | 17/6/2026 | ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerability in versions up to and including 3.3.2. This can not be exploited in a fresh install of PrestaShop, only shops made vulnerable by third party modules are concerned. For example, if the shop has a… | |
| Analizada | Alta (7.8) | 0.29% | — | Adobe Photoshop | 14/1/2025 | 17/6/2026 | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the… | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Photoshop | 14/1/2025 | 17/6/2026 | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (5.3) | 0.35% | — | Shopping Cart Ecommerce StoreAI | 8/1/2025 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses. | |
| Analizada | Media (5.3) | 0.41% | — | Fabian Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Online Book Shop 1.0. Affected by this issue is some unknown functionality of the file /subcat.php. The manipulation of the argument catnm leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.55% | — | Fabian Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /subcat.php. The manipulation of the argument cat leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.58% | — | Code-projects Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.91% | — | Code-projects Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the file /process_login.php. The manipulation of the argument usernm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.65% | — | Code-projects Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.69% | — | Code-projects Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /booklist.php. The manipulation of the argument subcatid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.46% | — | Code-projects Online Book Shop | 7/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /booklist.php?subcatid=1. The manipulation of the argument subcatnm leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.3) | 0.37% | — | Optimize Your Campaigns Google Shopping Google ADS Google AdwordsAI | 7/1/2025 | 17/6/2026 | The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to extract sensitive… |