Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.60% | — | Shopify Ruby LSP | 31/3/2026 | 17/6/2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project… | |
| Analizada | Media (5.3) | 0.33% | — | Prestashop | 26/3/2026 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available. | |
| Analizada | Media (5.4) | 0.40% | — | Prestashop | 26/3/2026 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit… | |
| Analizada | Alta (8.1) | 0.43% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain… | |
| Analizada | Alta (7.5) | 0.47% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Media (6.8) | 0.46% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Versions 1.41.1 and 2.41.1 contain a… | |
| Analizada | Media (4.8) | 0.35% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Alta (8.7) | 0.44% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Alta (8.8) | 0.79% | — | Opensource-workshop Connect-cms | 23/3/2026 | 17/6/2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch. | |
| Analizada | Media (5.7) | 0.44% | 💥 PoC | Bishopfox Sliver | 20/3/2026 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remote OOM (Out-of-Memory) vulnerability in the Sliver C2 server's mTLS and WireGuard C2 transport layer. The socketReadEnvelope and socketWGReadEnvelope functions trust an attacker-controlled 4-byte… | |
| Aplazada | Media (5.3) | 0.32% | — | Vowelweb VW PET ShopAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in vowelweb VW Pet Shop vw-pet-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Pet Shop: from n/a through <= 1.4.7. | |
| Aplazada | Media (5.3) | 0.33% | — | Radiustheme ShopbuilderAI | 13/3/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 3.2.4. | |
| Aplazada | Media (5.3) | 0.33% | — | ShopwareAI | 12/3/2026 | 17/6/2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15. | |
| Aplazada | Media (5.3) | 0.33% | — | ShopwareAI | 12/3/2026 | 17/6/2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7. | |
| Analizada | Alta (8.9) | 0.41% | — | Shopware | 11/3/2026 | 17/6/2026 | Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without… | |
| Analizada | Media (5.3) | 0.34% | — | Shopware | 11/3/2026 | 17/6/2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) or is unknown… | |
| Analizada | Alta (8.9) | 0.39% | — | Shopware | 11/3/2026 | 17/6/2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15. | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 8/3/2026 | 17/6/2026 | A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 8/3/2026 | 17/6/2026 | A weakness has been identified in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument Info causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the… | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be… | |
| Analizada | Baja (2.1) | 0.54% | 💥 PoC | Bishopfox Sliver | 7/3/2026 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a… | |
| Aplazada | Alta (8.8) | 0.24% | — | Ashop Shopping Cart SoftwareAI | 4/3/2026 | 17/6/2026 | Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive… | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 2/3/2026 | 17/6/2026 | A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.53% | — | Evershop | 26/2/2026 | 17/6/2026 | EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Version 2.1.1 fixes the issue. | |
| Analizada | Media (5.5) | 0.61% | — | Haben-cs9 Simple AND Nice Shopping Cart Script | 25/2/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. |