Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.83% | — | Myprestamodules Orders (csv, Excel) Export PRO | 20/3/2024 | 17/6/2026 | An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. | |
| Analizada | Crítica (9.8) | 0.56% | — | Fmemodules B2B Quick Order Form | 14/3/2024 | 17/6/2026 | SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods. | |
| Analizada | Crítica (9.8) | 0.53% | — | Myprestamodules Product Catalog (csv, Excel) Import | 3/3/2024 | 17/6/2026 | SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |
| Analizada | Crítica (9.1) | 0.79% | — | Myprestamodules Product Catalog (csv, Excel) Import | 27/2/2024 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |
| Modificada | Alta (7.8) | 0.17% | — | Hidglobal Iclass SE Cp1000 Encoder FirmwareHidglobal Iclass SE Readers FirmwareHidglobal Iclass SE Reader Modules FirmwareHidglobal Iclass SE Processors Firmware+4 | 6/2/2024 | 17/6/2026 | Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys. | |
| Modificada | Crítica (9.8) | 0.67% | — | Prestashopmodules Sliding Cart Block | 19/1/2024 | 17/6/2026 | In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection. | |
| Modificada | Alta (7.5) | 0.59% | — | Myprestamodules Orders (csv, Excel) Export PRO | 6/12/2023 | 17/6/2026 | In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from… | |
| Modificada | Media (5.3) | 0.50% | — | Blmodules CSV Feeds PRO | 27/11/2023 | 17/6/2026 | In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of… | |
| Modificada | Crítica (9.8) | 0.77% | — | Myprestamodules Updateproducts | 27/11/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Crítica (9.8) | 0.71% | — | Myprestamodules Cross Selling IN Modal Cart | 22/11/2023 | 17/6/2026 | In the module "Cross Selling in Modal Cart" (motivationsale) < 3.5.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `motivationsaleDataModel::getProductsByIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Crítica (9.8) | 0.71% | — | Myprestamodules Exportproducts | 17/11/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().` | |
| Analizada | Alta (8.8) | 0.67% | — | Myprestamodules Orders (csv, Excel) Export PRO | 15/11/2023 | 17/6/2026 | MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters. | |
| Modificada | Alta (7.5) | 0.47% | — | Smartmodules Facebookconversiontrackingplus | 2/11/2023 | 17/6/2026 | In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can… | |
| Modificada | Crítica (9.8) | 0.64% | — | Blmodules CSV Feeds PRO | 31/10/2023 | 17/6/2026 | In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Alta (7.5) | 0.80% | — | Myprestamodules Exportproducts | 25/10/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name… | |
| Modificada | Crítica (9.8) | 0.98% | — | Myprestamodules Product Catalog (csv, Excel) Import | 20/9/2023 | 17/6/2026 | SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php. | |
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Myprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts | 20/9/2023 | 17/6/2026 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | |
| Modificada | Crítica (9.8) | 0.81% | — | Blmodules Xmlfeeds PRO | 15/9/2023 | 17/6/2026 | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds(). | |
| Modificada | Crítica (9.8) | 1.2% | — | Myprestamodules Frequently Asked Questions Page | 31/3/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component. | |
| Modificada | Crítica (9.8) | 1.5% | — | Global-modules-path Project Global-modules-path | 13/1/2023 | 17/6/2026 | Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function. | |
| Modificada | Alta (8.8) | 2.2% | — | Dell Container Storage Modules | 11/10/2022 | 17/6/2026 | Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution. | |
| Modificada | Alta (8.8) | 1.6% | — | Dell Container Storage Modules | 11/10/2022 | 17/6/2026 | Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted… | |
| Modificada | Media (6.5) | 1.3% | — | Dell Container Storage Modules | 30/8/2022 | 17/6/2026 | Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory. | |
| Modificada | Alta (8.8) | 1.4% | — | Dell Container Storage Modules | 30/8/2022 | 17/6/2026 | Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system. | |
| Modificada | Crítica (9.8) | 2.1% | — | Deno Standard Modules | 11/10/2021 | 17/6/2026 | Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. |