Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Dell PowerstoreAI | 1/9/2026 | 4/9/2026 | Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Trtek Technological Products Products StoreAI | 1/9/2026 | 1/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. | |
| Analizada | Crítica (10) | 0.29% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access. | |
| Analizada | Alta (8.8) | 0.75% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.75% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.49% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. | |
| Analizada | Media (6.5) | 0.38% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information. | |
| Analizada | Alta (8.8) | 0.18% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.. | |
| Analizada | Alta (8.8) | 0.49% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. | |
| Analizada | Alta (8.8) | 0.26% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. | |
| Analizada | Alta (8.8) | 0.75% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.49% | — | Dell Powerstoreos | 1/9/2026 | 30/9/2026 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths. | |
| Analizada | Alta (8.8) | 0.53% | — | Dell Powerstoreos | 1/9/2026 | 30/9/2026 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerstoreos | 1/9/2026 | 30/9/2026 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. | |
| Aplazada | Media (4.9) | 0.27% | — | Shoppingcart Shopping Cart Ecommerce StoreAI | 1/9/2026 | 1/9/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.25% | — | Superstorefinder Super Store FinderAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | |
| Aplazada | Media (6.1) | 0.22% | — | Nooncarlett TechstoreAI | 31/8/2026 | 1/9/2026 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser. | |
| Analizada | Crítica (9.8) | 0.63% | — | Dell Powerstoreos | 31/8/2026 | 1/10/2026 | Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability… | |
| Aplazada | Media (6.5) | 0.17% | — | Inspireui Mstore APIAI | 29/8/2026 | 31/8/2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment… | |
| Aplazada | Media (6.5) | 0.17% | — | Inspireui Mstore APIAI | 29/8/2026 | 31/8/2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made. | |
| Aplazada | Alta (7.5) | 0.39% | — | StoregrowthAI | 27/8/2026 | 28/8/2026 | The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is… | |
| Aplazada | Alta (8.6) | 0.52% | 💥 PoC | J2storeAIJoomlaAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray()… | |
| Aplazada | Media (5.1) | 0.54% | — | J2storeAIJoomlaAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication… | |
| Aplazada | Media (6.9) | 0.21% | — | J2storeAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and… | |
| Aplazada | Media (6.3) | 0.41% | — | J2storeAIJoomlaAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked. |