Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System22/3/202317/6/2026
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.62%—Prestashop EO Tags21/3/202317/6/2026
El paquete de etiquetas eo_tags antes de 1.4.19 para PrestaShop permite la inyección de SQL a través de una cookie _ga manipulada.
ModificadaCrítica (9.8)0.87%—Prestashop EO Tags21/3/202317/6/2026
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
ModificadaCrítica (9.8)0.72%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script19/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.55%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart16/3/202317/6/2026
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it…
ModificadaAlta (8.8)0.90%—Prestashop Advanced Reviews14/3/202317/6/2026
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)0.89%—Prestashop DPD France13/3/202317/6/2026
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
ModificadaAlta (8.8)0.22%—Prestashop13/3/202317/6/2026
PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF…
ModificadaCrítica (9.8)0.55%—Simple Bakery Shop Management System Project Simple Bakery Shop Management System12/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Bakery Shop Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation of the argument username/password with the input admin' or 1=1 -- leads to sql injection. The…
ModificadaAlta (7.2)0.70%—Sul1ss Shop Project Sul1ss Shop8/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SUL1SS_shop. This issue affects some unknown processing of the file application\merch\controller\Order.php. The manipulation of the argument keyword leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.56%—Phone Shop Sales Managements System Project Phone Shop Sales Managements System8/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vulnerability affects unknown code of the file /osms/assets/plugins/jquery-validation-1.11.1/demo/captcha/index.php of the component CAPTCHA Handler. The manipulation leads to cross site scripting. The…
ModificadaAlta (8.8)0.88%—Prestashop XEN Forum6/3/202317/6/2026
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
ModificadaAlta (8.8)0.75%—Shopex Ecshop6/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (8.8)0.75%—Shopex Ecshop6/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has…
ModificadaMedia (6.1)0.56%—Online PET Shop WE APP Project Online PET Shop WE APP26/2/202317/6/2026
A vulnerability has been found in SourceCodester Online Pet Shop We App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /pet_shop/admin/orders/update_status.php. The manipulation of the argument oid with the input 1"><script>alert(1111)</script> leads to cross site scripting. The…
ModificadaAlta (8.8)0.78%—Oretnom23 Online Eyewear Shop22/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=orders/view_order. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has…
ModificadaMedia (6.1)1.2%💥 ExploitArtisanworkshop Japanized FOR Woocommerce21/2/202317/6/2026
The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaCrítica (9.8)3.3%—Hasthemes Shoplentor21/2/202317/6/2026
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
ModificadaMedia (5.4)0.53%—Hasthemes Shoplentor21/2/202317/6/2026
The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.33%—Adobe Photoshop17/2/202317/6/2026
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must…
ModificadaMedia (5.5)0.31%—Adobe Photoshop17/2/202317/6/2026
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must…
ModificadaAlta (7.8)0.30%—Adobe Photoshop17/2/202317/6/2026
Photoshop versiones 23.5.3 (y anteriores) y 24.1 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. es requerida una interacción del usuario para la explotación de este problema, ya que la…
ModificadaAlta (7.8)0.30%—Adobe Photoshop17/2/202317/6/2026
Photoshop versiones 23.5.3 (y anteriores) y 24.1 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. es requerida una interacción del usuario para la explotación de este problema, ya que la…
ModificadaAlta (7.8)0.33%—Adobe Photoshop17/2/202317/6/2026
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (8.8)0.26%—Lightspeedhq Ecwid Ecommerce Shopping Cart14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
Orbitaley — Vulnerabilidades