Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.51% | — | Multivendorx Product Catalog Enquiry FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2. | |
| Modificada | Crítica (9.1) | 0.32% | — | Multivendorx Product Catalog Mode FOR Woocommerce | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.5. | |
| Aplazada | Alta (7.1) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eCommerce Product Catalog: from n/a through 3.3.32. | |
| Aplazada | Media (4.3) | 0.20% | — | Etoilewebdesign Ultimate Product CatalogueAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15. | |
| Aplazada | Media (4.3) | 0.21% | — | Implecode Ecommerce Product CatalogAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28. | |
| Analizada | Crítica (9.8) | 0.53% | — | Myprestamodules Product Catalog (csv, Excel) Import | 3/3/2024 | 17/6/2026 | SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |
| Analizada | Crítica (9.1) | 0.79% | — | Myprestamodules Product Catalog (csv, Excel) Import | 27/2/2024 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |
| Modificada | Alta (7.5) | 0.48% | — | Implecode Ecommerce Product Catalog | 29/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26. | |
| Modificada | Alta (7.5) | 0.48% | — | Implecode Product Catalog Simple | 29/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue affects Product Catalog Simple: from n/a through 1.7.6. | |
| Modificada | Media (6.1) | 0.53% | — | Multivendorx Product Catalog Mode FOR Woocommerce | 18/12/2023 | 17/6/2026 | The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users. | |
| Modificada | Alta (8.8) | 0.25% | — | Pixelyoursite Product Catalog Feed | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1. | |
| Modificada | Media (5.4) | 0.38% | — | Maevelander WP Catalogue | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnigmaWeb WP Catalogue allows Stored XSS.This issue affects WP Catalogue: from n/a through 1.7.6. | |
| Modificada | Media (6.5) | 0.28% | — | Implecode Ecommerce Product Catalog | 4/12/2023 | 17/6/2026 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products | |
| Modificada | Media (5.4) | 0.41% | — | Implecode Ecommerce Product Catalog | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.26 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Goods Catalog Project Goods Catalog | 29/9/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Irina Sokolovskaya Goods Catalog plugin <= 2.4.1 versions. | |
| Modificada | Alta (8.8) | 1.7% | 💥 PoC | Webcatalog | 28/9/2023 | 17/6/2026 | WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances. | |
| Modificada | Crítica (9.8) | 0.98% | — | Myprestamodules Product Catalog (csv, Excel) Import | 20/9/2023 | 17/6/2026 | SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php. | |
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Myprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts | 20/9/2023 | 17/6/2026 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | |
| Modificada | Crítica (9.8) | 0.80% | — | Simple Book Catalog APP Project Simple Book Catalog APP | 9/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Book Catalog App 1.0. Affected by this vulnerability is an unknown functionality of the file delete_book.php. The manipulation of the argument delete leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.1) | 0.60% | — | Simple Book Catalog APP Project Simple Book Catalog APP | 9/9/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Simple Book Catalog App 1.0. Affected is an unknown function of the component Update Book Form. The manipulation of the argument book_title/book_author leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.46% | — | Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio | 31/7/2023 | 17/6/2026 | The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.8) | 0.50% | — | IBM Watson Knowledge Catalog ON Cloud PAK FOR Data | 10/7/2023 | 17/6/2026 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782. | |
| Modificada | Media (6.5) | 0.98% | — | IBM Watson Knowledge Catalog ON Cloud PAK FOR Data | 10/7/2023 | 17/6/2026 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. | |
| Modificada | Media (4.3) | 0.48% | — | Implecode Ecommerce Product Catalog | 1/7/2023 | 17/6/2026 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save manual digital orders… | |
| Modificada | Media (4.3) | 0.48% | — | Implecode Ecommerce Product Catalog | 1/7/2023 | 17/6/2026 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save… |