Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.45% | — | Themerex Sound Musical Instruments Online StoreAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9. | |
| Aplazada | Alta (7.1) | 0.21% | — | Extremeidea BidorbuystoreintegratorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Reflected XSS.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0. | |
| Analizada | Media (5.5) | 6.9% | — | Tosei-corporation Online Store Management System | 19/1/2026 | 17/6/2026 | A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of the file /cgi-bin/imode_alldata.php. Executing a manipulation of the argument DevId can lead to command injection. The attack can be executed remotely. The exploit has been publicly… | |
| Aplazada | Alta (8.8) | 0.16% | — | Epic Games StoreAIMicrosoft StoreAI | 15/1/2026 | 17/6/2026 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges. | |
| Analizada | Media (5.1) | 0.28% | — | Zippy Zstore | 13/1/2026 | 17/6/2026 | Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context. | |
| Aplazada | Media (4.3) | 0.29% | — | Dwbooster CP Image Store With SlideshowAI | 13/1/2026 | 17/6/2026 | The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for authenticated attackers, with Contributor-level access and above, to import… | |
| Analizada | Media (5.5) | 0.11% | — | Sigstore Cosign | 10/1/2026 | 17/6/2026 | Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key. When verifying a Rekor entry, Cosign verifies… | |
| Analizada | Media (5.1) | 0.16% | — | Samsung Galaxy Store | 9/1/2026 | 17/6/2026 | Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script. | |
| Aplazada | Media (4.3) | 0.19% | — | Bdthemes Ultimate Store KITAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.9.4. | |
| Analizada | Media (5.5) | 0.38% | — | Anisha Online Guitar Store | 1/1/2026 | 7/10/2026 | A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Modificada | Media (5.5) | 0.42% | — | Anisha Online Guitar Store | 1/1/2026 | 7/10/2026 | A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql injection. The attack may be performed from remote. The exploit has been publicly… | |
| Modificada | Media (5.5) | 0.38% | — | Anisha Online Guitar Store | 1/1/2026 | 7/10/2026 | A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.38% | — | Anisha Online Guitar Store | 1/1/2026 | 7/10/2026 | A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument dre_Ctitle leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.9) | 0.21% | — | Plainware Locatoraid Store LocatorAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware Locatoraid Store Locator locatoraid allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.68. | |
| Aplazada | Media (6.5) | 0.16% | — | Zookatron Mybooktable BookstoreAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0. | |
| Aplazada | Media (6.5) | 0.16% | — | 8theme Xstore CoreAI | 30/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6. | |
| Analizada | Media (6.1) | 0.22% | — | Nooncarlett Techstore | 23/12/2025 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML response without output encoding or sanitization, allowing execution of arbitrary JavaScript code in a victim’s browser. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Flex Store UsersAI | 20/12/2025 | 17/6/2026 | The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what user roles a user can register with. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.5) | 0.46% | — | 8theme XstoreAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in 8theme XStore xstore allows PHP Local File Inclusion.This issue affects XStore: from n/a through < 9.6.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | 8theme XstoreAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows Reflected XSS.This issue affects XStore: from n/a through < 9.6.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | 8theme Xstore CoreAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through < 5.6. | |
| Aplazada | Media (6.3) | 0.22% | — | 8theme XstoreAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects XStore: from n/a through < 9.6. | |
| Analizada | Alta (8.6) | 0.34% | — | Wavestore Video Management Software Server | 16/12/2025 | 17/6/2026 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in the ilog script. This script is being run with root privileges. This issue was… | |
| Analizada | Media (5.1) | 0.39% | — | Wavestore Video Management Software Server | 16/12/2025 | 17/6/2026 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete files, with the permissions of dvr user, on the server using path traversal in the alog script. This issue was fixed in… | |
| Analizada | Alta (8.6) | 0.49% | — | Wavestore Video Management Software Server | 16/12/2025 | 17/6/2026 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script. This issue was fixed in version 6.44.44 |