Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.26% | — | Youlai-mall | 4/12/2025 | 25/9/2026 | A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the argument memberId leads to improper access controls. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Baja (2.1) | 0.47% | — | Youlai-mall | 4/12/2025 | 17/6/2026 | A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be executed remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.30% | — | Macrozheng Mall-swarm | 4/12/2025 | 17/6/2026 | A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.… | |
| Aplazada | Media (5) | 0.15% | — | Smallstep Step CAAI | 3/12/2025 | 17/6/2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0. | |
| Analizada | Media (5.1) | 0.21% | 💥 PoC | Smallbasic | 3/12/2025 | 17/6/2026 | Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information leakage and crash. | |
| Analizada | Media (6.1) | 0.18% | — | Exrick Xmall | 29/11/2025 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scripts. | |
| Analizada | Baja (2.1) | 0.23% | — | Macrozheng Mall | 20/11/2025 | 17/6/2026 | A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. | |
| Analizada | Media (6.1) | 0.22% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Small CRM | 17/11/2025 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | |
| Modificada | Baja (2.1) | 0.24% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 0.30% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file /order/cancelOrder. The manipulation of the argument orderId leads to improper authorization. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.30% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of the argument orderId can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available… | |
| Analizada | Baja (2.1) | 0.33% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.24% | — | Macrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /cart/update/attr. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about… | |
| Aplazada | Media (5.3) | 0.35% | — | GE Vernova SmallworldAI | 7/11/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions. | |
| Aplazada | Crítica (9.3) | 0.50% | — | GE Vernova SmallworldAI | 7/11/2025 | 17/6/2026 | Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows. | |
| Aplazada | Baja (2.9) | 0.46% | — | Newbee-ltd Newbee-mall-plusAI | 7/11/2025 | 17/6/2026 | A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill of the file /seckillExecution/. The manipulation of the argument userid leads to authorization bypass. It is possible to initiate the attack remotely. The attack is considered to have high complexity.… | |
| Aplazada | Baja (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 27/10/2025 | 17/6/2026 | A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 27/10/2025 | 17/6/2026 | A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument category_id can lead to cross site… | |
| Analizada | Alta (8.1) | 0.53% | — | Thememove Edumall | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall allows PHP Local File Inclusion.This issue affects EduMall: from n/a through < 4.4.5. | |
| Analizada | Media (6.5) | 0.36% | — | Ghostxbh Uzy-ssm-mall | 8/10/2025 | 17/6/2026 | A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input. | |
| Analizada | Media (6.5) | 0.35% | — | Ghostxbh Uzy-ssm-mall | 8/10/2025 | 17/6/2026 | An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data. | |
| Analizada | Media (6.5) | 0.49% | — | Yiovo Firefly Mall | 2/10/2025 | 17/6/2026 | YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b)… |