Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.33% | — | Online Store System CMSAI | 26/3/2026 | 17/6/2026 | Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind… | |
| Aplazada | Media (6.5) | 0.34% | — | Kaira StorecustomizerAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects StoreCustomizer: from n/a through <= 2.6.3. | |
| Aplazada | Alta (7.1) | 0.18% | — | 8theme Xstore CoreAI8theme Et-core-pluginAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Axiomthemes M2 Construction AND Tools StoreAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.5) | 0.51% | — | Wpxpo WowstoreAI | 17/3/2026 | 17/6/2026 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Analizada | Media (5.9) | 0.07% | 💥 PoC | Samsung Galaxy Store | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application. | |
| Analizada | Media (5.9) | 0.12% | 💥 PoC | Samsung Galaxy Store | 16/3/2026 | 17/6/2026 | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. | |
| Analizada | Alta (7) | 0.13% | — | Samsung Galaxy Store | 16/3/2026 | 17/6/2026 | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. | |
| Analizada | Alta (7.5) | 0.42% | — | Sigstore | 10/3/2026 | 17/6/2026 | sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the VerificationFailure returned by verify_in_toto when the artifact digest does not match the digest in the in-toto attestation subject. As a… | |
| Analizada | Media (4.9) | 0.35% | — | Suse Rancher Backup AND Restore Operator | 4/3/2026 | 17/6/2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. | |
| Analizada | Media (5.5) | 7.3% | — | Tosei-corporation Online Store Management System | 22/2/2026 | 17/6/2026 | A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file /cgi-bin/monitor.php of the component HTTP POST Request Handler. Performing a manipulation of the argument DevId results in os command injection. The attack may be initiated… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themeex Lorem Ipsum Books Media StoreAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themerex Extreme StoreAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.10. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Teconceappstore AllmartAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind SQL Injection.This issue affects Allmart: from n/a through <= 1.1. | |
| Analizada | Baja (3.7) | 0.21% | — | Sigstore Cosign | 19/2/2026 | 17/6/2026 | Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issuing certificate should be considered… | |
| Aplazada | Media (6.5) | 0.17% | — | 8theme Xstore CoreAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7. | |
| Aplazada | Media (6.5) | 0.17% | — | 8theme XstoreAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through <= 9.6.4. | |
| Aplazada | Media (5.3) | 0.24% | — | 8theme XstoreAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4. | |
| Aplazada | Media (5.3) | 0.23% | — | Mega StoreAI | 19/2/2026 | 17/6/2026 | The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widgets() function in core/includes/importer/whizzie.php in all versions up to, and including, 5.9. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.8) | 0.41% | — | Infor Storefront B2BAI | 30/1/2026 | 17/6/2026 | Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database… | |
| Analizada | Crítica (9.8) | 0.58% | — | Carmelo Computer Book Store | 27/1/2026 | 17/6/2026 | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. | |
| Analizada | Media (5) | 0.18% | — | Linuxfoundation Sigstore-python | 26/1/2026 | 17/6/2026 | sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the authentication request but the "state" in… | |
| Aplazada | Media (5.3) | 0.20% | — | Themebeez Orchid StoreAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in themebeez Orchid Store orchid-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Orchid Store: from n/a through <= 1.5.15. | |
| Aplazada | Media (5.8) | 0.40% | — | SigstoreAISigstore CosignAI | 23/1/2026 | 17/6/2026 | sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target name sourced from signed target metadata;… | |
| Aplazada | Media (5.4) | 0.11% | — | Storeapps Woocommerce Stock ManagerAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Manager for WooCommerce: from n/a through < 3.6.0. |