Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.45% | — | StoregrowthAI | 28/7/2026 | 28/7/2026 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | |
| Aplazada | Alta (7.2) | 0.46% | — | StoregrowthAI | 28/7/2026 | 28/7/2026 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (5.3) | 0.40% | — | Storegrowth Sales BoosterAI | 28/7/2026 | 28/7/2026 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users… | |
| Aplazada | Alta (7.5) | 0.39% | — | Shopfiles Ebook StoreAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | |
| Aplazada | Crítica (9.3) | 1.0% | 💥 Exploit | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. | |
| Aplazada | Crítica (9.2) | 0.42% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system. | |
| Aplazada | Alta (8.7) | 0.43% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders. | |
| Aplazada | Media (5.3) | 0.33% | — | Ultimate Store KIT Elementor AddonsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Ultimate Store KIT Elementor AddonsAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Istore | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability… | |
| Analizada | Media (5.3) | 0.28% | — | Oracle Istore | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Istore | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Istore | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability… | |
| Analizada | Media (4.3) | 0.27% | — | Oracle Retail Xstore Point OF Service | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of… | |
| Analizada | Baja (3.3) | 0.14% | — | Oracle Retail Xstore Point OF Service | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service… | |
| Aplazada | Alta (7.1) | 0.27% | — | Syslog-ngAIBalabit Syslog-ng Premium EditionAIOneidentity Syslog-ng Store BOXAI | 20/7/2026 | 23/7/2026 | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver… | |
| Analizada | Alta (7.5) | 0.18% | — | Sigstore-go | 17/7/2026 | 30/7/2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a single compromised transparency log or CT… | |
| Analizada | Alta (7.5) | 0.74% | — | Linuxfoundation Sigstore Timestamp Authority | 17/7/2026 | 30/7/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote… | |
| Aplazada | Alta (7.3) | 0.13% | — | Lenovo Legion ZoneAILenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code. | |
| Aplazada | Alta (7) | 0.17% | — | Lenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Aplazada | Alta (7) | 0.18% | — | Lenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code. | |
| Aplazada | Media (6.5) | 0.16% | — | Sigstore-jsAI | 14/7/2026 | 15/7/2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime,… | |
| Aplazada | Alta (7.5) | 0.19% | — | Sigstore-jsAI | 14/7/2026 | 15/7/2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on… |