Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.51% | — | Prestashop | 7/8/2023 | 17/6/2026 | PrestaShop es una aplicación web de comercio electrónico de código abierto. Las versiones anteriores a 1.7.8.10, 8.0.5, y 8.1.1 son vulnerables a Cross-Site Scripting (XSS) a través del método "isCleanHTML". Las versiones 1.7.8.10, 8.0.5 y 8.1.1 contienen un parche. No se conocen soluciones. | |
| Modificada | Crítica (9.8) | 1.7% | 💥 PoC | Prestashop | 7/8/2023 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds. | |
| Modificada | Crítica (9.1) | 0.86% | — | Prestashop | 7/8/2023 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch for this issue. There are no known… | |
| Modificada | Crítica (9.8) | 0.66% | — | Prestashop | 7/8/2023 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds. | |
| Modificada | Media (6.5) | 0.45% | — | Palantir Magritte-rest-source-bundle | 3/8/2023 | 17/6/2026 | The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE). | |
| Modificada | Media (6.1) | 0.41% | — | Fivestarplugins Five Star Restaurant Menu | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions. | |
| Modificada | Media (5.3) | 0.75% | — | Prestashop Amazon | 25/7/2023 | 17/6/2026 | An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack. | |
| Modificada | Crítica (9.8) | 1.0% | — | Prestashop Payplug | 18/7/2023 | 17/6/2026 | An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller. | |
| Modificada | Alta (7.5) | 0.62% | — | Crestron Cp3n 6505417 FirmwareCrestron CP3 6504877 FirmwareCrestron Cp3-gv 6506034 Firmware | 17/7/2023 | 17/6/2026 | On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash. | |
| Modificada | Alta (8.8) | 0.26% | — | Fivestarplugins Five Star Restaurant Menu | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions. | |
| Modificada | Media (6.1) | 0.49% | — | Liquidweb Restrict Content | 17/7/2023 | 17/6/2026 | The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 1.1% | — | Wpeverest User Registration | 13/7/2023 | 17/6/2026 | El plugin User Registration para WordPress es vulnerable a la inyección de objetos PHP en versiones hasta la 3.0.1 inclusive a través de la deserialización de la entrada no fiable del parámetro "profile-pic-url". Esto permite a atacantes autenticados, con permisos de nivel de suscriptor y superiores, inyectar un… | |
| Modificada | Crítica (9.9) | 1.7% | — | Wpeverest User Registration | 13/7/2023 | 17/6/2026 | El plugin User Registration para WordPress es vulnerable a la carga de archivos arbitrarios debido a una clave de cifrado codificada y a la falta de validación del tipo de archivo en la función "ur_upload_profile_pic" en las versiones hasta la 3.0.2 inclusive. Esto hace posible que atacantes autenticados con… | |
| Modificada | Alta (8.8) | 0.40% | — | Jenkins Pipeline Restful API | 12/7/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attackers to connect to an attacker-specified URL, capturing a newly generated JCLI token. | |
| Modificada | Crítica (9.8) | 0.89% | — | Code-projects Online Restaurant Management System | 12/7/2023 | 17/6/2026 | Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc. | |
| Modificada | Crítica (9.9) | 0.85% | — | Zope Restrictedpython | 11/7/2023 | 17/6/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which… | |
| Modificada | Media (6.1) | 0.38% | — | Everestthemes Arya Multipurpose | 16/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose theme <= 1.0.5 versions. | |
| Modificada | Alta (7.5) | 0.71% | — | Cloudflare Lua-resty-json | 14/6/2023 | 17/6/2026 | A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug… | |
| Modificada | Crítica (9.8) | 4.5% | 💥 Exploit | Valvepress Pinterest Automatic PIN | 7/6/2023 | 17/6/2026 | The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary… | |
| Modificada | Crítica (9.8) | 0.60% | — | Scfixmyprestashop Project Scfixmyprestashop | 25/5/2023 | 17/6/2026 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | |
| Modificada | Crítica (9.8) | 0.29% | — | Thingsforrestaurants Quick Restaurant Reservations | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Prestashop Possearchproducts | 12/5/2023 | 17/6/2026 | Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Prestashop Poststaticfooter | 10/5/2023 | 17/6/2026 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | |
| Modificada | Media (6.1) | 0.38% | — | Everestthemes Viable Blog | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Viable Blog theme <= 1.1.4 versions. | |
| Modificada | Alta (7.5) | 0.56% | — | Prestashop Scexportcustomers | 4/5/2023 | 17/6/2026 | PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports from the module which can lead to leak of personal information from customer table. |