Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

1646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.62%—Storecommander Customers Export25/5/202317/6/2026
In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
ModificadaCrítica (9.8)3.8%💥 ExploitInspireui Mstore API25/5/202317/6/2026
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as…
ModificadaCrítica (9.8)1.2%—Inspireui Mstore API25/5/202317/6/2026
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any…
ModificadaCrítica (9.8)68%💥 ExploitInspireui Mstore API25/5/202317/6/2026
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any…
ModificadaAlta (8.8)0.27%—Viadat Store Locator FOR Wordpress With Google Maps24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.
ModificadaMedia (6.1)0.55%—Online Jewelry Store Project Online Jewelry Store24/5/202317/6/2026
A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file customer.php of the component POST Parameter Handler. The manipulation of the argument Custid leads to cross site scripting. The attack may be launched…
ModificadaAlta (7.5)0.29%—Keruistore Kerui W18 Firmware24/5/202317/6/2026
Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.
ModificadaCrítica (9.8)0.73%—Online Jewelry Store Project Online Jewelry Store19/5/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Online Jewelry Store 1.0. Affected by this vulnerability is an unknown functionality of the file supplier.php of the component POST Parameter Handler. The manipulation of the argument suppid leads to sql injection. The attack can be launched remotely.…
ModificadaMedia (6.5)0.47%—Storecommander Scquickaccounting16/5/202317/6/2026
Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table sush as name / surname / email
ModificadaCrítica (9.8)1.5%—Oretnom23 Online Computer AND Laptop Store16/5/202317/6/2026
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.
ModificadaMedia (4.8)0.37%—Shopfiles Ebook Store15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions.
ModificadaCrítica (9.8)0.82%—Oretnom23 Online Computer AND Laptop Store11/5/202317/6/2026
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.82%—Oretnom23 Online Computer AND Laptop Store11/5/202317/6/2026
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This vulnerability affects unknown code of the file view_categories.php. The manipulation of the argument c leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.82%—Oretnom23 Online Computer AND Laptop Store11/5/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file view_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.88%—Oretnom23 Online Computer AND Laptop Store11/5/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file products.php. The manipulation of the argument c leads to sql injection. The attack may be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.70%—Oretnom23 Online Computer AND Laptop Store11/5/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. The manipulation of the argument search leads to cross site scripting. The attack can be launched remotely. The exploit has…
ModificadaAlta (7.5)0.68%—Shieldstore Project Shieldstore9/5/20239/7/2026
A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaAlta (8.8)0.73%—Oretnom23 Online Computer AND Laptop Store22/4/202317/6/2026
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation of the argument c/s leads to sql injection. The attack can be launched remotely. The…
ModificadaAlta (7.5)0.61%—Campcodes Retro Basketball Shoes Online Store21/4/202331/7/2026
A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…