Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.41% | — | J2storeAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to render the full checkout confirmation page for that order, including line items, prices, and totals. | |
| Aplazada | Media (5.3) | 0.19% | 💥 PoC | J2storeAI | 21/8/2026 | 26/8/2026 | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also lacked a CSRF token. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Locatoraid Store LocatorAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Nikstore CoreAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | |
| Pendiente de análisis | Alta (8.1) | 0.40% | — | Dell PowerstoreAI | 18/8/2026 | 20/8/2026 | Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. | |
| Pendiente de análisis | Alta (8.1) | 0.61% | — | Dell Powerstore SdnasAI | 18/8/2026 | 31/8/2026 | Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service. | |
| Pendiente de análisis | Crítica (9.8) | 0.83% | — | Dell Powerstore SdnasAI | 18/8/2026 | 31/8/2026 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet… | |
| Aplazada | Media (6.5) | 1.1% | — | StoreengineAI | 16/8/2026 | 20/8/2026 | The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to… | |
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.53% | — | Sourcecodester Online Clothing StoreAI | 15/8/2026 | 20/8/2026 | A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the… | |
| Aplazada | Media (6.3) | 0.17% | — | Restore-repoAI | 13/8/2026 | 26/8/2026 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | |
| Aplazada | Alta (7.5) | 0.35% | — | Storegrowth Smart Sales Booster FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | |
| Aplazada | Alta (8.1) | 0.37% | — | Inspireui Mstore APIAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | |
| Aplazada | Alta (8.7) | 0.28% | — | Sigstore FulcioAI | 13/8/2026 | 9/9/2026 | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute… | |
| Aplazada | Baja (2) | 0.07% | — | Sigstore-javaAI | 13/8/2026 | 9/9/2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verification with enhancements that adhere to the Sigstore verification spec. The old… | |
| Aplazada | Media (5.5) | 0.56% | — | Sourcecodester Online Clothing StoreAIAdobe DreamweaverAI | 7/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (7.5) | 0.36% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept… | |
| Aplazada | Media (6.5) | 0.34% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. | |
| Aplazada | Alta (8.1) | 0.38% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. | |
| Aplazada | Media (6.5) | 0.27% | — | Ultimate Store KIT Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Superstorefinder Super Store FinderAI | 3/8/2026 | 31/8/2026 | The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database. | |
| Pendiente de análisis | Baja (3.1) | 0.13% | — | Sigstore-goAI | 31/7/2026 | 10/9/2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign… | |
| Aplazada | Media (6.4) | 0.33% | — | Wpxpo WowstoreAI | 29/7/2026 | 30/7/2026 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Wpxpo WowstoreAI | 29/7/2026 | 30/7/2026 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… |