Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.48% | — | Kids Gift ShopAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | EmallshopAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Themeton THE Barber ShopAI | 17/6/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. | |
| Aplazada | Alta (8.1) | 0.43% | — | WineshopAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in WineShop <= 3.17 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Fabian Simple Shopping CartAI | 15/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions. | |
| Aplazada | Media (5.5) | 0.29% | — | ShopxoAI | 15/6/2026 | 24/7/2026 | A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be… | |
| Aplazada | Baja (3.7) | 0.36% | — | ShopwareAI | 10/6/2026 | 23/7/2026 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue. | |
| Aplazada | Baja (2.1) | 0.20% | — | BeikeshopAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.value results in sql injection. It is possible to… | |
| Aplazada | Media (5.5) | 0.29% | — | Stripe PluginAIBeikeshopAI | 7/6/2026 | 23/7/2026 | A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can… | |
| Aplazada | Baja (2.1) | 0.30% | — | Projectworlds Online ART Gallery ShopAI | 4/6/2026 | 22/7/2026 | A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument social_twitter results in sql injection. The attack may be launched remotely. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.30% | — | Projectworlds Online ART Gallery Shop ProjectAI | 4/6/2026 | 22/7/2026 | A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be… | |
| Aplazada | Alta (8.2) | 0.55% | 💥 PoC | CoreshopAIPimcoreAI | 4/6/2026 | 6/10/2026 | CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dangerously checks out the unverified code from the pull request head (`ref: ${{ github.event.pull_request.head.ref }}`).… | |
| Analizada | Alta (7.5) | 0.46% | — | Shopify React-routerShopify Remix-run/server-runtime | 2/6/2026 | 21/7/2026 | React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation… | |
| Analizada | Alta (8.1) | 0.62% | — | Shopify React-router | 2/6/2026 | 21/7/2026 | React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can… | |
| Analizada | Media (6.6) | 0.27% | — | Shopify React-router | 2/6/2026 | 4/8/2026 | React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation… | |
| Analizada | Alta (7.5) | 0.45% | — | Shopify React-routerTurbo-stream Turbo Stream | 2/6/2026 | 22/7/2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications… | |
| Analizada | Media (4.7) | 0.23% | — | Shopify React-router | 2/6/2026 | 22/7/2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications… | |
| Analizada | Media (5.4) | 0.14% | — | Shopify React-router | 2/6/2026 | 21/7/2026 | React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source.… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Computer Repair Shop Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be… | |
| Aplazada | Media (6.5) | 0.31% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticated panel user without checking the corresponding per-action permission. A… | |
| Aplazada | Crítica (9.9) | 0.42% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new… | |
| Aplazada | Media (6.5) | 0.31% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping… | |
| Aplazada | Media (5.9) | 0.31% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under concurrent checkout pressure (Black Friday, flash sale, viral coupon), the global usage_limit was silently exceeded:… | |
| Aplazada | Alta (8.1) | 0.36% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment,… | |
| Aplazada | Media (6.9) | 0.16% | — | Phpshop Php-shopAI | 29/5/2026 | 21/7/2026 | PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php… |