Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.83%—Myprestamodules Orders (csv, Excel) Export PRO20/3/202417/6/2026
An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.
AnalizadaCrítica (9.8)0.56%—Fmemodules B2B Quick Order Form14/3/202417/6/2026
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
AnalizadaCrítica (9.8)0.53%—Myprestamodules Product Catalog (csv, Excel) Import3/3/202417/6/2026
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
AnalizadaCrítica (9.1)0.79%—Myprestamodules Product Catalog (csv, Excel) Import27/2/202417/6/2026
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
ModificadaAlta (7.8)0.17%—Hidglobal Iclass SE Cp1000 Encoder FirmwareHidglobal Iclass SE Readers FirmwareHidglobal Iclass SE Reader Modules FirmwareHidglobal Iclass SE Processors Firmware+46/2/202417/6/2026
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
ModificadaCrítica (9.8)0.67%—Prestashopmodules Sliding Cart Block19/1/202417/6/2026
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.
ModificadaAlta (7.5)0.59%—Myprestamodules Orders (csv, Excel) Export PRO6/12/202317/6/2026
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from…
ModificadaMedia (5.3)0.50%—Blmodules CSV Feeds PRO27/11/202317/6/2026
In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of…
ModificadaCrítica (9.8)0.77%—Myprestamodules Updateproducts27/11/202317/6/2026
In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaCrítica (9.8)0.71%—Myprestamodules Cross Selling IN Modal Cart22/11/202317/6/2026
In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::getProductsByIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaCrítica (9.8)0.71%—Myprestamodules Exportproducts17/11/202317/6/2026
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`
AnalizadaAlta (8.8)0.67%—Myprestamodules Orders (csv, Excel) Export PRO15/11/202317/6/2026
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
ModificadaAlta (7.5)0.47%—Smartmodules Facebookconversiontrackingplus2/11/202317/6/2026
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can…
ModificadaCrítica (9.8)0.64%—Blmodules CSV Feeds PRO31/10/202317/6/2026
In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaAlta (7.5)0.80%—Myprestamodules Exportproducts25/10/202317/6/2026
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name…
ModificadaCrítica (9.8)0.98%—Myprestamodules Product Catalog (csv, Excel) Import20/9/202317/6/2026
SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.
ModificadaAlta (7.5)32%💥 ExploitMyprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts20/9/202317/6/2026
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
ModificadaCrítica (9.8)0.81%—Blmodules Xmlfeeds PRO15/9/202317/6/2026
Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().
ModificadaCrítica (9.8)1.2%—Myprestamodules Frequently Asked Questions Page31/3/202317/6/2026
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.
ModificadaCrítica (9.8)1.5%—Global-modules-path Project Global-modules-path13/1/202317/6/2026
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
ModificadaAlta (8.8)2.2%—Dell Container Storage Modules11/10/202217/6/2026
Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.
ModificadaAlta (8.8)1.6%—Dell Container Storage Modules11/10/202217/6/2026
Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted…
ModificadaMedia (6.5)1.3%—Dell Container Storage Modules30/8/202217/6/2026
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.
ModificadaAlta (8.8)1.4%—Dell Container Storage Modules30/8/202217/6/2026
Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.
ModificadaCrítica (9.8)2.1%—Deno Standard Modules11/10/202117/6/2026
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
Orbitaley — Vulnerabilidades