Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Alta (7.5) | 0.56% | — | Prestashop Scexportcustomers | 4/5/2023 | 17/6/2026 | PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports from the module which can lead to leak of personal information from customer table. | |
| Modificada | Alta (8.8) | 1.7% | 💥 PoC | Prestashop | 25/4/2023 | 17/6/2026 | PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds. | |
| Modificada | Crítica (9.9) | 1.0% | — | Prestashop | 25/4/2023 | 17/6/2026 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML… | |
| Modificada | Media (6.5) | 0.86% | — | Prestashop | 25/4/2023 | 17/6/2026 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user… | |
| Modificada | Crítica (9.8) | 0.73% | — | Oretnom23 Online Eyewear Shop | 22/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. This affects an unknown part of the file /admin/orders/update_status.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Media (6.1) | 0.58% | 💥 PoC | Shopware | 21/4/2023 | 17/6/2026 | Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI. | |
| Modificada | Media (6.1) | 0.65% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php. The manipulation of the argument firstname leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.6% | 💥 PoC | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/sales/manage_sale.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/products/manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability has been found in Campcodes Coffee Shop POS System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/categories/view_category.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/sales/view_details.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.36% | — | Online Jewelry Shop Project Online Jewelry Shop | 19/4/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL. | |
| Modificada | Media (5.4) | 0.48% | — | Online Jewelry Shop Project Online Jewelry Shop | 19/4/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter. | |
| Modificada | Crítica (9.8) | 0.75% | — | Shoppingfeed | 18/4/2023 | 17/6/2026 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There… | |
| Modificada | Alta (8.8) | 2.1% | — | Shopware | 17/4/2023 | 17/6/2026 | Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in… | |
| Modificada | Media (5.4) | 0.36% | — | Oxidforge Oxid Eshop | 11/4/2023 | 17/6/2026 | OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent. | |
| Modificada | Crítica (9.8) | 0.78% | — | Oretnom23 Online Eyewear Shop | 10/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file /admin/inventory/manage_stock.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 7/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The… | |
| Modificada | Crítica (9.1) | 0.64% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 7/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This vulnerability affects unknown code of the file delete_user_query.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 30/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.8) | 0.46% | — | Adobe Photoshop | 27/3/2023 | 17/6/2026 | Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |