Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 22/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.62% | — | Prestashop EO Tags | 21/3/2023 | 17/6/2026 | El paquete de etiquetas eo_tags antes de 1.4.19 para PrestaShop permite la inyección de SQL a través de una cookie _ga manipulada. | |
| Modificada | Crítica (9.8) | 0.87% | — | Prestashop EO Tags | 21/3/2023 | 17/6/2026 | The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. | |
| Modificada | Crítica (9.8) | 0.72% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 19/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (5.3) | 0.55% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 16/3/2023 | 17/6/2026 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it… | |
| Modificada | Alta (8.8) | 0.90% | — | Prestashop Advanced Reviews | 14/3/2023 | 17/6/2026 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.89% | — | Prestashop DPD France | 13/3/2023 | 17/6/2026 | PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. | |
| Modificada | Alta (8.8) | 0.22% | — | Prestashop | 13/3/2023 | 17/6/2026 | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF… | |
| Modificada | Crítica (9.8) | 0.55% | — | Simple Bakery Shop Management System Project Simple Bakery Shop Management System | 12/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Bakery Shop Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation of the argument username/password with the input admin' or 1=1 -- leads to sql injection. The… | |
| Modificada | Alta (7.2) | 0.70% | — | Sul1ss Shop Project Sul1ss Shop | 8/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SUL1SS_shop. This issue affects some unknown processing of the file application\merch\controller\Order.php. The manipulation of the argument keyword leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.56% | — | Phone Shop Sales Managements System Project Phone Shop Sales Managements System | 8/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vulnerability affects unknown code of the file /osms/assets/plugins/jquery-validation-1.11.1/demo/captcha/index.php of the component CAPTCHA Handler. The manipulation leads to cross site scripting. The… | |
| Modificada | Alta (8.8) | 0.88% | — | Prestashop XEN Forum | 6/3/2023 | 17/6/2026 | In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. | |
| Modificada | Alta (8.8) | 0.75% | — | Shopex Ecshop | 6/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.8) | 0.75% | — | Shopex Ecshop | 6/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.56% | — | Online PET Shop WE APP Project Online PET Shop WE APP | 26/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pet Shop We App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /pet_shop/admin/orders/update_status.php. The manipulation of the argument oid with the input 1"><script>alert(1111)</script> leads to cross site scripting. The… | |
| Modificada | Alta (8.8) | 0.78% | — | Oretnom23 Online Eyewear Shop | 22/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=orders/view_order. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 21/2/2023 | 17/6/2026 | The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Crítica (9.8) | 3.3% | — | Hasthemes Shoplentor | 21/2/2023 | 17/6/2026 | The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection. | |
| Modificada | Media (5.4) | 0.53% | — | Hasthemes Shoplentor | 21/2/2023 | 17/6/2026 | The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Photoshop | 17/2/2023 | 17/6/2026 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Media (5.5) | 0.31% | — | Adobe Photoshop | 17/2/2023 | 17/6/2026 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Photoshop | 17/2/2023 | 17/6/2026 | Photoshop versiones 23.5.3 (y anteriores) y 24.1 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. es requerida una interacción del usuario para la explotación de este problema, ya que la… | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Photoshop | 17/2/2023 | 17/6/2026 | Photoshop versiones 23.5.3 (y anteriores) y 24.1 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. es requerida una interacción del usuario para la explotación de este problema, ya que la… | |
| Modificada | Alta (7.8) | 0.33% | — | Adobe Photoshop | 17/2/2023 | 17/6/2026 | Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (8.8) | 0.26% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions. |