Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
1646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.62% | — | Storecommander Customers Export | 25/5/2023 | 17/6/2026 | In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Inspireui Mstore API | 25/5/2023 | 17/6/2026 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as… | |
| Modificada | Crítica (9.8) | 1.2% | — | Inspireui Mstore API | 25/5/2023 | 17/6/2026 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any… | |
| Modificada | Crítica (9.8) | 68% | 💥 Exploit | Inspireui Mstore API | 25/5/2023 | 17/6/2026 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any… | |
| Modificada | Alta (8.8) | 0.27% | — | Viadat Store Locator FOR Wordpress With Google Maps | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions. | |
| Modificada | Media (6.1) | 0.55% | — | Online Jewelry Store Project Online Jewelry Store | 24/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file customer.php of the component POST Parameter Handler. The manipulation of the argument Custid leads to cross site scripting. The attack may be launched… | |
| Modificada | Alta (7.5) | 0.29% | — | Keruistore Kerui W18 Firmware | 24/5/2023 | 17/6/2026 | Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack. | |
| Modificada | Crítica (9.8) | 0.73% | — | Online Jewelry Store Project Online Jewelry Store | 19/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Jewelry Store 1.0. Affected by this vulnerability is an unknown functionality of the file supplier.php of the component POST Parameter Handler. The manipulation of the argument suppid leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Media (6.5) | 0.47% | — | Storecommander Scquickaccounting | 16/5/2023 | 17/6/2026 | Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email | |
| Modificada | Crítica (9.8) | 1.5% | — | Oretnom23 Online Computer AND Laptop Store | 16/5/2023 | 17/6/2026 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save. | |
| Modificada | Media (4.8) | 0.37% | — | Shopfiles Ebook Store | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This vulnerability affects unknown code of the file view_categories.php. The manipulation of the argument c leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.82% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file view_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.88% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file products.php. The manipulation of the argument c leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.70% | — | Oretnom23 Online Computer AND Laptop Store | 11/5/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. The manipulation of the argument search leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Modificada | Alta (7.5) | 0.68% | — | Shieldstore Project Shieldstore | 9/5/2023 | 9/7/2026 | A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Online Computer AND Laptop Store | 22/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation of the argument c/s leads to sql injection. The attack can be launched remotely. The… | |
| Modificada | Alta (7.5) | 0.61% | — | Campcodes Retro Basketball Shoes Online Store | 21/4/2023 | 31/7/2026 | A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… |