Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.26%—Sigstore-jsAISigstore CoreAI14/7/202615/7/2026
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE string to bytes, allowing payloadType to be mutated after signing without invalidating the signature and breaking the…
Pendiente de análisisCrítica (9.6)0.47%💥 PoCSigstore-jsAI14/7/202621/7/2026
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an…
AplazadaMedia (6.5)0.27%—Inspireui Mstore APIAI13/7/202613/7/2026
Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.
AplazadaBaja (2.1)0.42%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php…
AplazadaBaja (2)0.40%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been…
AplazadaMedia (5.5)0.43%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used…
AplazadaBaja (1.9)0.37%—Sourcecodester Online Book Store SystemAI13/7/202613/7/2026
A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and…
AplazadaCrítica (9.4)0.14%—Xenproject OxenstoredAI9/7/20269/7/2026
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.
AplazadaCrítica (9.4)0.14%—XEN VarstoredAITianocore OvmfAI9/7/202629/9/2026
varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers, creating TOCTOU issues with data in the shared buffer. The exact vulnerable…
AplazadaMedia (4.9)0.50%—FaissAIFlowise SimplestoreAIFlowiseai FlowiseAI8/7/20269/7/2026
Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations, potentially enabling code execution or…
Pendiente de análisisCrítica (9.8)0.81%—Nvidia AistoreAI1/7/20261/7/2026
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
AplazadaAlta (8.7)0.65%—Dcmtk StorescpAI30/6/20261/7/2026
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
Pendiente de análisisAlta (8)1.3%—Dell Csi-powerstoreAIDell Csi-unityAIDell Csi-powerflexAIDell Csi-powermaxAI26/6/202626/6/2026
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially…
AplazadaAlta (7.7)0.22%💥 PoCGrocery Store Management System Using PHP AND Mysql PhpmyadminAI25/6/202626/6/2026
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
AplazadaAlta (8.5)0.17%—Vembu StoregridAI19/6/202629/9/2026
Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and restart the service to execute code with LocalSystem privileges.
AplazadaMedia (6.5)0.46%—Inspireui Mstore APIAI17/6/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.
Pendiente de análisisMedia (5.4)0.20%—Dell PowerstoreAI16/6/20261/10/2026
PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser.
AplazadaCrítica (9.9)0.48%—Themagnifico52 Kids Online StoreAI16/6/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
AplazadaBaja (3.4)0.37%—Store LocatorAI13/6/202621/7/2026
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
AplazadaBaja (3.5)0.24%—Store LocatorAI13/6/202621/7/2026
The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the…
AplazadaMedia (4.3)0.18%—Sparkle WP MetrostoreAI11/6/202626/9/2026
Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.
AplazadaBaja (3.5)0.24%—Store LocatorAI10/6/202623/7/2026
The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the…
AplazadaAlta (8.6)1.6%💥 Exploit8theme XstoreAI10/6/202623/7/2026
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
AplazadaCrítica (9.1)1.1%—Cluster-admin Backup-datastoreAI5/6/202617/6/2026
An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.
AplazadaBaja (1.9)0.11%—Bytedance InfinistoreAI5/6/202623/7/2026
A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a manipulation results in inefficient algorithmic complexity. The attack requires a local approach. The exploit has been made…