Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.60% | — | Sanchitkmr Shopping Website | 7/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.94% | — | Sanchitkmr Shopping Website | 4/7/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 0.65% | — | Sanchitkmr Shopping Website | 4/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.87% | — | Sanchitkmr Shopping Website | 29/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file forgot-password.php. The manipulation of the argument contact leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.87% | — | Sanchitkmr Shopping Website | 29/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.3) | 0.65% | — | Shopware | 27/6/2023 | 17/6/2026 | Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it was possible to construct different mail addresses, that in the end result in the same address, which is shared by multiple accounts. This issue has been addressed in version 5.7.18 and users are… | |
| Modificada | Media (5.3) | 0.61% | — | Shopware | 27/6/2023 | 17/6/2026 | Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the specific Shopware version in a deployment might be determined by an… | |
| Modificada | Crítica (9.8) | 0.69% | — | Online Shopping System Advanced Project Online Shopping System Advanced | 20/6/2023 | 17/6/2026 | A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched… | |
| Modificada | Media (5.4) | 0.59% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 18/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.77% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 7/6/2023 | 17/6/2026 | The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logo_width, logo_height, rcsp_logo_url, home_sec_link_txt, rcsp_headline and rcsp_description parameters in versions up to, and including, 1.8.1 due to insufficient input sanitization and output… | |
| Modificada | Media (5.3) | 0.81% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 7/6/2023 | 17/6/2026 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset. | |
| Modificada | Alta (8.8) | 0.27% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (5.4) | 0.36% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level. | |
| Modificada | Crítica (9.1) | 0.53% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. | |
| Modificada | Crítica (9.8) | 0.68% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. | |
| Modificada | Media (5.4) | 0.34% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za. | |
| Modificada | Media (5.3) | 0.75% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm. | |
| Modificada | Crítica (9.8) | 0.60% | — | Scfixmyprestashop Project Scfixmyprestashop | 25/5/2023 | 17/6/2026 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpmet Shopengine | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Studiowombat Shoppable Images | 18/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Shopfiles Ebook Store | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Prestashop Possearchproducts | 12/5/2023 | 17/6/2026 | Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Prestashop Poststaticfooter | 10/5/2023 | 17/6/2026 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | |
| Modificada | Alta (7.1) | 0.71% | — | Yershop Project Yershop | 9/5/2023 | 17/6/2026 | Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter. | |
| Modificada | Media (5.4) | 0.39% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 8/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions. |