Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.38% | — | IwebshopAI | 8/9/2026 | 8/9/2026 | A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the… | |
| Aplazada | Media (5.5) | 0.69% | — | IwebshopAI | 8/9/2026 | 8/9/2026 | A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The… | |
| Aplazada | Baja (2.1) | 0.47% | — | IwebshopAI | 8/9/2026 | 11/9/2026 | A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2) | 0.35% | — | IwebshopAI | 8/9/2026 | 8/9/2026 | A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public… | |
| Aplazada | Media (5.5) | 0.54% | — | IwebshopAI | 8/9/2026 | 10/9/2026 | A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The… | |
| Aplazada | Media (5.5) | 0.54% | — | IwebshopAI | 8/9/2026 | 8/9/2026 | A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was… | |
| Aplazada | Alta (8.1) | 0.48% | — | BSH ELPAI | 30/7/2026 | 30/7/2026 | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private… | |
| Analizada | Crítica (9.3) | 0.67% | — | Mohibshaikh Clawvet | 17/7/2026 | 14/8/2026 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest… | |
| Modificada | Alta (7) | 0.26% | — | M-files Hubshare | 15/9/2025 | 17/6/2026 | Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users. | |
| Analizada | Baja (1.3) | 0.48% | — | Totalwebshield Total Webshield | 9/8/2025 | 17/6/2026 | A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (5.3) | 0.33% | — | Beijing Longda Jushang Technology DbshopAI | 27/12/2024 | 17/6/2026 | A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as problematic. This vulnerability affects unknown code of the file /home-order. The manipulation of the argument orderStatus with the input %22%3E%3Csvg%20onload=alert(5888)%3E leads to cross site… | |
| Modificada | Media (6.9) | 0.29% | — | M-files Hubshare | 2/10/2024 | 17/6/2026 | Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI | |
| Modificada | Alta (8.5) | 0.35% | — | M-files Hubshare | 29/7/2024 | 17/6/2026 | Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session | |
| Modificada | Alta (8.5) | 0.30% | — | M-files Hubshare | 29/7/2024 | 17/6/2026 | Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session | |
| Modificada | Alta (7) | 0.31% | — | M-files Hubshare | 24/5/2024 | 17/6/2026 | Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser | |
| Modificada | Crítica (9.8) | 0.52% | — | Webshopworks Creativepopup | 19/10/2023 | 17/6/2026 | In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform SQL injection via `cp_download_popup().` | |
| Modificada | Media (5.4) | 0.40% | — | Webshouters WS Facebook Like BOX Widget | 15/9/2023 | 17/6/2026 | The WS Facebook Like Box Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ws-facebook-likebox' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.5) | 0.41% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server. | |
| Modificada | Alta (7.5) | 0.43% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL. | |
| Modificada | Media (5.4) | 0.40% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments. | |
| Modificada | Alta (8.8) | 0.55% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload. | |
| Modificada | Baja (2.7) | 0.80% | — | Five Minute Webshop Project Five Minute Webshop | 8/6/2022 | 17/6/2026 | The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection | |
| Modificada | Media (4.9) | 0.99% | — | Five Minute Webshop Project Five Minute Webshop | 8/6/2022 | 17/6/2026 | The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection | |
| Modificada | Alta (8.8) | 0.71% | — | Iwebshop | 31/8/2021 | 17/6/2026 | Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'. | |
| Modificada | Media (6.1) | 1.7% | — | Dragonbyte-tech Vbshout Module | 11/1/2018 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1) reportreason parameter in actions/doreport.php or (2) modnotes parameter in… |