Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.42%—Dell PowerstoreAI1/9/20264/9/2026
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AplazadaCrítica (9.8)0.36%—Trtek Technological Products Products StoreAI1/9/20261/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.
AnalizadaCrítica (10)0.29%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
AnalizadaAlta (8.8)0.75%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AnalizadaAlta (8.8)0.75%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AnalizadaAlta (8.8)0.49%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
AnalizadaMedia (6.5)0.38%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.
AnalizadaAlta (8.8)0.18%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
AnalizadaAlta (8.8)0.49%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
AnalizadaAlta (8.8)0.26%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.
AnalizadaAlta (8.8)0.75%—Dell Powerstoreos1/9/20262/10/2026
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AnalizadaAlta (8.8)0.49%—Dell Powerstoreos1/9/202630/9/2026
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.
AnalizadaAlta (8.8)0.53%—Dell Powerstoreos1/9/202630/9/2026
Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
AnalizadaAlta (8.8)0.42%—Dell Powerstoreos1/9/202630/9/2026
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
AplazadaMedia (4.9)0.27%—Shoppingcart Shopping Cart Ecommerce StoreAI1/9/20261/9/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaAlta (7.1)0.25%—Superstorefinder Super Store FinderAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
AplazadaMedia (6.1)0.22%—Nooncarlett TechstoreAI31/8/20261/9/2026
TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser.
AnalizadaCrítica (9.8)0.63%—Dell Powerstoreos31/8/20261/10/2026
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability…
AplazadaMedia (6.5)0.17%—Inspireui Mstore APIAI29/8/202631/8/2026
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment…
AplazadaMedia (6.5)0.17%—Inspireui Mstore APIAI29/8/202631/8/2026
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made.
AplazadaAlta (7.5)0.39%—StoregrowthAI27/8/202628/8/2026
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is…
AplazadaAlta (8.6)0.52%💥 PoCJ2storeAIJoomlaAI21/8/202626/8/2026
Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray()…
AplazadaMedia (5.1)0.54%—J2storeAIJoomlaAI21/8/202626/8/2026
Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication…
AplazadaMedia (6.9)0.21%—J2storeAI21/8/202626/8/2026
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and…
AplazadaMedia (6.3)0.41%—J2storeAIJoomlaAI21/8/202626/8/2026
Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.