Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

1646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.0%—Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+2013/9/202317/6/2026
Una vulnerabilidad de Desbordamiento del Búfer en el servicio de red Wibu CodeMeter Runtime hasta la versión 7.60b permite a un atacante remoto no autenticado lograr RCE y obtener acceso completo al sistema anfitrión.
ModificadaAlta (7.8)0.18%—Samsung Blockchain Keystore6/9/202317/6/2026
La falla del mecanismo de protección en bc_tui trustlet de Samsung Blockchain Keystore anterior a la version 1.3.13.5 permite a un atacante local ejecutar código arbitrario.
ModificadaCrítica (9.8)0.99%💥 PoCSuperstorefinder Super Store Finder5/9/202317/6/2026
Se descubrió que Super Store Finder v3.6 contiene múltiples vulnerabilidades de inyección SQL en el componente "store locator" a través de los parámetros "products", "distance", "lat" y "lng".
ModificadaCrítica (9.8)1.4%💥 PoCSuperstorefinder Super Store Finder5/9/202317/6/2026
Una contraseña incrustada en Super Store Finder v3.6 permite a los atacantes acceder al panel de administración.
ModificadaMedia (6.1)0.69%💥 ExploitAgilelogix Store Locator4/9/202317/6/2026
El plugin Store Locator para WordPress anterior a la versión 1.4.13 no sanitiza ni escapa un nonce inválido antes de devolverlo en una respuesta AJAX, lo que da lugar a un Cross-Site Scripting (XSS) reflejado que podría utilizarse contra usuarios con privilegios elevados, como los administradores.
ModificadaMedia (6.1)1.0%💥 ExploitAjaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
Todo lo anterior: Tema de WordPress de Aapna hasta 1.3, Tema de WordPress de Anand hasta 1.2, Tema de WordPress de Anfaust hasta 1.1, Tema de WordPress de Arendelle antes de 1.1.13, Tema de WordPress de Atlast Business hasta 1.5.8.5, Tema de WordPress de Bazaar Lite antes de 1.8.6, Tema de WordPress de Brain Power…
ModificadaMedia (5.4)0.36%—Plainwaire Locatoraid Store Locator25/8/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada en el plugin Locatoraid Store Locator de Plainware que afecta a las versiones 3.9.18 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de suscriptor o superior.
ModificadaCrítica (9.8)0.76%—Oppo Store10/8/202317/6/2026
A remote code execution vulnerability in the webview component of OPPO Store app.
ModificadaCrítica (9.8)0.76%—Oneplus Store10/8/202317/6/2026
A remote code execution vulnerability in the webview component of OnePlus Store app.
ModificadaMedia (5.5)0.15%—Samsung Galaxy Store10/8/202317/6/2026
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.
ModificadaMedia (6.1)9.1%💥 ExploitMoosocial Moostore6/8/202317/6/2026
Se ha encontrado una vulnerabilidad en mooSocial mooStore v3.1.6 y se ha clasificado como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida. La manipulación conduce a Cross-Site Scripting (XSS). El ataque puede lanzarse de forma remota. Se ha asignado a esta vulnerabilidad el identificador…
ModificadaMedia (6.1)5.4%💥 ExploitMoosocial Moostore6/8/202317/6/2026
Se ha encontrado una vulnerabilidad, clasificada como problemática, en mooSocial mooStore v3.1.6. Se ve afectada una función desconocida del archivo /search/index. La manipulación del argumento "q" conduce a Cross-Site Scripting (XSS). Es posible lanzar el ataque de forma remota. El identificador de esta…
ModificadaMedia (6.1)0.62%—Jewelry Store System Project Jewelry Store System28/7/202317/6/2026
A vulnerability was found in SourceCodester Jewelry Store System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add_customer.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-235610 is the identifier assigned to this…
ModificadaCrítica (9.8)0.94%—Online Jewelry Store Project Online Jewelry Store28/7/202317/6/2026
A vulnerability has been found in SourceCodester Online Jewelry Store 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (4.9)0.54%—Dell Powerstoreos21/7/202317/6/2026
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.
ModificadaCrítica (9.8)0.50%—Superstorefinder Super Store Finder19/7/202317/6/2026
A vulnerability was found in Super Store Finder 3.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component POST Parameter Handler. The manipulation of the argument products leads to sql injection. The attack can be launched remotely. The…
ModificadaMedia (6.1)0.56%—Retro Cellphone Online Store Project Retro Cellphone Online Store15/7/202317/6/2026
A vulnerability classified as problematic was found in Campcodes Retro Cellphone Online Store 1.0. This vulnerability affects unknown code of the file /admin/modal_add_product.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)1.3%💥 PoCOretnom23 Online Computer AND Laptop Store13/7/202317/6/2026
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
ModificadaAlta (7.5)0.65%—Entetsu Store13/7/20239/7/2026
An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.
ModificadaAlta (7.5)0.65%—Shizutetsu Store13/7/20239/7/2026
An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
ModificadaAlta (7.5)0.65%—Keisei Store Livre13/7/20239/7/2026
An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
ModificadaMedia (6.1)0.52%—Retro Cellphone Online Store Project Retro Cellphone Online Store13/7/202317/6/2026
A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been…
ModificadaMedia (4.3)0.30%—Inspireui Mstore API12/7/202317/6/2026
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_firebase_server_key function. This makes it possible for unauthenticated attackers to update the firebase server key to push notification when order status changed via a forged request…
ModificadaMedia (4.3)0.30%—Inspireui Mstore API12/7/202317/6/2026
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_title function. This makes it possible for unauthenticated attackers to update status order title via a forged request granted they can trick a site administrator into…
ModificadaAlta (8.8)0.27%—Storeapps Stock Manager FOR Woocommerce11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions.