Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.84% | — | Marshmallow-packages Nova-tiptapAILaravel NovaAI | 21/7/2025 | 17/6/2026 | marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshmallow-packages/nova-tiptap Laravel Nova package that allows unauthenticated users to upload arbitrary files to any Laravel disk configured in the application. The… | |
| Aplazada | Alta (8.5) | 0.37% | 💥 Exploit | Pandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI | 15/7/2025 | 17/6/2026 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.… | |
| Analizada | Baja (2.1) | 0.40% | — | Linlinjava Litemall | 26/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of the argument adminComment leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.45% | — | Phpgurukul Small CRM | 27/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown processing of the file /admin/manage-tickets.php. The manipulation of the argument aremark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (6.9) | 0.45% | — | Phpgurukul Small CRM | 27/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-password.php. The manipulation of the argument oldpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.3) | 0.56% | — | Project Team Tmall Demo | 25/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of… | |
| Analizada | Media (4.8) | 0.34% | — | Project Team Tmall Demo | 24/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of the file /tmall/admin/ of the component Product Details Page. The manipulation of the argument Product Name/Product Title leads to cross site scripting. The attack… | |
| Analizada | Media (5.1) | 0.33% | — | Project Team Tmall Demo | 24/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy Item Page. The manipulation of the argument Detailed Address leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.43% | — | Project Team Tmall Demo | 24/5/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is… | |
| Analizada | Media (5.3) | 0.31% | — | Project Team Tmall Demo | 24/5/2025 | 17/6/2026 | A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmall/admin/account/logout. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.1) | 0.55% | — | Project Team Tmall Demo | 24/5/2025 | 17/6/2026 | A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage of the file tmall/admin/uploadCategoryImage. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.1) | 0.47% | — | Project Team Tmall Demo | 24/5/2025 | 17/6/2026 | A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file tmall/admin/uploadProductImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.54% | — | Exrick Xmall | 5/5/2025 | 17/6/2026 | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. | |
| Analizada | Media (5.3) | 0.53% | — | Newbee-mall Project Newbee-mall | 5/5/2025 | 17/6/2026 | A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.3) | 0.36% | — | Weitong MallAI | 30/4/2025 | 17/6/2026 | A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The manipulation of the argument ID leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.65% | — | Weitong Mall | 30/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. The attack can be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.67% | — | Weitong Mall | 30/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component Product History Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (8.1) | 0.88% | — | Thememove EdumallAI | 26/4/2025 | 17/6/2026 | The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via the 'template' parameter of the 'edumall_lazy_load_template' AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the… | |
| Analizada | Crítica (9.8) | 0.61% | — | Exrick Xmall | 15/4/2025 | 17/6/2026 | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | |
| Analizada | Media (5.3) | 0.34% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted… | |
| Analizada | Media (5.1) | 0.40% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the argument product_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.59% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/product/0/20. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.7) | 0.17% | — | Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+257 | 9/4/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Aplazada | Media (6.5) | 0.38% | — | Enituretechnology Small Package Quotes Worldwide Express EditionAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.19. |