Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

1172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.51%—Prestashop7/8/202317/6/2026
PrestaShop es una aplicación web de comercio electrónico de código abierto. Las versiones anteriores a 1.7.8.10, 8.0.5, y 8.1.1 son vulnerables a Cross-Site Scripting (XSS) a través del método "isCleanHTML". Las versiones 1.7.8.10, 8.0.5 y 8.1.1 contienen un parche. No se conocen soluciones.
ModificadaCrítica (9.8)1.7%💥 PoCPrestashop7/8/202317/6/2026
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
ModificadaCrítica (9.1)0.86%—Prestashop7/8/202317/6/2026
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch for this issue. There are no known…
ModificadaCrítica (9.8)0.66%—Prestashop7/8/202317/6/2026
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
ModificadaMedia (6.5)0.45%—Palantir Magritte-rest-source-bundle3/8/202317/6/2026
The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).
ModificadaMedia (6.1)0.41%—Fivestarplugins Five Star Restaurant Menu25/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
ModificadaMedia (5.3)0.75%—Prestashop Amazon25/7/202317/6/2026
An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.
ModificadaCrítica (9.8)1.0%—Prestashop Payplug18/7/202317/6/2026
An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller.
ModificadaAlta (7.5)0.62%—Crestron Cp3n 6505417 FirmwareCrestron CP3 6504877 FirmwareCrestron Cp3-gv 6506034 Firmware17/7/202317/6/2026
On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.
ModificadaAlta (8.8)0.26%—Fivestarplugins Five Star Restaurant Menu17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
ModificadaMedia (6.1)0.49%—Liquidweb Restrict Content17/7/202317/6/2026
The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (8.8)1.1%—Wpeverest User Registration13/7/202317/6/2026
El plugin User Registration para WordPress es vulnerable a la inyección de objetos PHP en versiones hasta la 3.0.1 inclusive a través de la deserialización de la entrada no fiable del parámetro "profile-pic-url". Esto permite a atacantes autenticados, con permisos de nivel de suscriptor y superiores, inyectar un…
ModificadaCrítica (9.9)1.7%—Wpeverest User Registration13/7/202317/6/2026
El plugin User Registration para WordPress es vulnerable a la carga de archivos arbitrarios debido a una clave de cifrado codificada y a la falta de validación del tipo de archivo en la función "ur_upload_profile_pic" en las versiones hasta la 3.0.2 inclusive. Esto hace posible que atacantes autenticados con…
ModificadaAlta (8.8)0.40%—Jenkins Pipeline Restful API12/7/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attackers to connect to an attacker-specified URL, capturing a newly generated JCLI token.
ModificadaCrítica (9.8)0.89%—Code-projects Online Restaurant Management System12/7/202317/6/2026
Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc.
ModificadaCrítica (9.9)0.85%—Zope Restrictedpython11/7/202317/6/2026
RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which…
ModificadaMedia (6.1)0.38%—Everestthemes Arya Multipurpose16/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose theme <= 1.0.5 versions.
ModificadaAlta (7.5)0.71%—Cloudflare Lua-resty-json14/6/202317/6/2026
A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug…
ModificadaCrítica (9.8)4.5%💥 ExploitValvepress Pinterest Automatic PIN7/6/202317/6/2026
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary…
ModificadaCrítica (9.8)0.60%—Scfixmyprestashop Project Scfixmyprestashop25/5/202317/6/2026
In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
ModificadaCrítica (9.8)0.29%—Thingsforrestaurants Quick Restaurant Reservations22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 versions.
ModificadaCrítica (9.8)2.7%💥 ExploitPrestashop Possearchproducts12/5/202317/6/2026
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
ModificadaCrítica (9.8)32%💥 ExploitPrestashop Poststaticfooter10/5/202317/6/2026
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
ModificadaMedia (6.1)0.38%—Everestthemes Viable Blog10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Viable Blog theme <= 1.1.4 versions.
ModificadaAlta (7.5)0.56%—Prestashop Scexportcustomers4/5/202317/6/2026
PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports from the module which can lead to leak of personal information from customer table.