Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.51%—Multivendorx Product Catalog Enquiry FOR WoocommerceAI9/12/202417/6/2026
Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.
ModificadaCrítica (9.1)0.32%—Multivendorx Product Catalog Mode FOR Woocommerce9/6/202417/6/2026
Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.5.
AplazadaAlta (7.1)0.37%—Implecode Ecommerce Product CatalogAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eCommerce Product Catalog: from n/a through 3.3.32.
AplazadaMedia (4.3)0.20%—Etoilewebdesign Ultimate Product CatalogueAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15.
AplazadaMedia (4.3)0.21%—Implecode Ecommerce Product CatalogAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28.
AnalizadaCrítica (9.8)0.53%—Myprestamodules Product Catalog (csv, Excel) Import3/3/202417/6/2026
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
AnalizadaCrítica (9.1)0.79%—Myprestamodules Product Catalog (csv, Excel) Import27/2/202417/6/2026
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
ModificadaAlta (7.5)0.48%—Implecode Ecommerce Product Catalog29/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26.
ModificadaAlta (7.5)0.48%—Implecode Product Catalog Simple29/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue affects Product Catalog Simple: from n/a through 1.7.6.
ModificadaMedia (6.1)0.53%—Multivendorx Product Catalog Mode FOR Woocommerce18/12/202317/6/2026
The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
ModificadaAlta (8.8)0.25%—Pixelyoursite Product Catalog Feed17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
ModificadaMedia (5.4)0.38%—Maevelander WP Catalogue14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnigmaWeb WP Catalogue allows Stored XSS.This issue affects WP Catalogue: from n/a through 1.7.6.
ModificadaMedia (6.5)0.28%—Implecode Ecommerce Product Catalog4/12/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products
ModificadaMedia (5.4)0.41%—Implecode Ecommerce Product Catalog23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.26 versions.
ModificadaMedia (5.4)0.36%—Goods Catalog Project Goods Catalog29/9/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Irina Sokolovskaya Goods Catalog plugin <= 2.4.1 versions.
ModificadaAlta (8.8)1.7%💥 PoCWebcatalog28/9/202317/6/2026
WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
ModificadaCrítica (9.8)0.98%—Myprestamodules Product Catalog (csv, Excel) Import20/9/202317/6/2026
SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.
ModificadaAlta (7.5)32%💥 ExploitMyprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts20/9/202317/6/2026
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
ModificadaCrítica (9.8)0.80%—Simple Book Catalog APP Project Simple Book Catalog APP9/9/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Simple Book Catalog App 1.0. Affected by this vulnerability is an unknown functionality of the file delete_book.php. The manipulation of the argument delete leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaMedia (6.1)0.60%—Simple Book Catalog APP Project Simple Book Catalog APP9/9/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Simple Book Catalog App 1.0. Affected is an unknown function of the component Update Book Form. The manipulation of the argument book_title/book_author leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaMedia (6.1)0.46%—Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio31/7/202317/6/2026
The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.8)0.50%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
ModificadaMedia (6.5)0.98%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
ModificadaMedia (4.3)0.48%—Implecode Ecommerce Product Catalog1/7/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save manual digital orders…
ModificadaMedia (4.3)0.48%—Implecode Ecommerce Product Catalog1/7/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save…
Orbitaley — Vulnerabilidades