Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.0% | 💥 Exploit | Compop Online MallAI | 4/2/2025 | 17/6/2026 | An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters. | |
| Analizada | Media (6.5) | 0.48% | — | Macrozheng Mall-tiny | 31/1/2025 | 17/6/2026 | In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require authentication, which triggers a denial-of-service attack and service restart failure. | |
| Analizada | Alta (8.8) | 0.46% | — | Macrozheng Mall-tiny | 31/1/2025 | 17/6/2026 | macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator. | |
| Analizada | Alta (7.5) | 0.44% | — | Macrozheng Mall-tiny | 31/1/2025 | 17/6/2026 | macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state. | |
| Analizada | Alta (7.5) | 0.53% | — | Macrozheng Mall-tiny | 31/1/2025 | 17/6/2026 | macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass. | |
| Aplazada | Crítica (9.3) | 0.41% | — | Enituretechnology Small Package Quotes WWE EditionAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows SQL Injection.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.17. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Enituretechnology Small Package Quotes Unishippers EditionAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Small Package Quotes – Unishippers Edition small-package-quotes-unishippers-edition allows SQL Injection.This issue affects Small Package Quotes – Unishippers Edition: from n/a through <= 2.4.8. | |
| Aplazada | Crítica (9.9) | 0.65% | — | Enrico Sandoli Smallerik File BrowserAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web Shell to a Web Server.This issue affects Smallerik File Browser: from n/a through <= 1.1. | |
| Analizada | Media (5.1) | 0.29% | — | Starsea99 Starsea-mall | 12/1/2025 | 17/6/2026 | A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/categories/update. The manipulation of the argument categoryName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.1) | 0.41% | — | Starsea99 Starsea-mall | 12/1/2025 | 17/6/2026 | A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file src/main/java/com/siro/mall/controller/common/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack can be… | |
| Aplazada | Media (6.9) | 0.53% | — | YunzmallAI | 9/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to weak password recovery. The attack… | |
| Analizada | Media (5.3) | 0.44% | — | Phpgurukul Small CRM | 29/12/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.51% | — | Phpgurukul Small CRM | 29/12/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Small CRM 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/quote-details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.51% | — | Phpgurukul Small CRM | 29/12/2024 | 17/6/2026 | A vulnerability has been found in PHPGurukul Small CRM 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.3) | 0.73% | — | Macrozheng Mall | 22/11/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of the component JWT Token Handler. The manipulation leads to use of default cryptographic key. The complexity of an attack is rather high. The exploitation is known… | |
| Aplazada | Media (6.1) | 0.44% | — | Cisco Small Business Rv042AICisco Small Business Rv042gAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV042 Dual WAN VPN Routers and Cisco Small Business RV042G Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management… | |
| Modificada | Alta (7.5) | 1.6% | — | Pickmall Lilishop | 15/11/2024 | 17/6/2026 | lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency. | |
| Analizada | Crítica (9.8) | 1.0% | — | Guchengwuyue Yshopmall | 15/11/2024 | 17/6/2026 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. | |
| Analizada | Alta (8.1) | 0.34% | — | Newbee-mall Project Newbee-mall | 28/10/2024 | 17/6/2026 | newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter. | |
| Modificada | Alta (7.5) | 0.63% | — | Linlinjava Litemall | 19/9/2024 | 17/6/2026 | A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java. | |
| Analizada | Alta (8.8) | 0.58% | — | Cisco IOS XRCisco Network Services OrchestratorCisco Small Business RV Series Router Firmware | 11/9/2024 | 17/6/2026 | This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications… | |
| Analizada | Media (5.3) | 0.49% | — | Project Team Tmall Demo | 8/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Analizada | Alta (7.3) | 0.26% | — | Project Team Tmall Demo | 15/7/2024 | 17/6/2026 | Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability. | |
| Analizada | Media (5.3) | 0.28% | — | Project Team Tmall Demo | 15/7/2024 | 17/6/2026 | Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability. |