Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.53% | — | BookcarsAI | 9/6/2026 | 23/7/2026 | An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. | |
| Aplazada | Media (5.3) | 0.69% | — | BookcarsAI | 9/6/2026 | 23/7/2026 | An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences. | |
| Aplazada | Alta (8.8) | 1.4% | — | BookcarsAI | 9/6/2026 | 23/7/2026 | An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbitrary locations on the server filesystem. This enables unauthorized access to sensitive files, the… | |
| Aplazada | Media (5.4) | 0.30% | — | BookcarsAI | 9/6/2026 | 23/7/2026 | An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Aplazada | Crítica (9.8) | 0.40% | — | BookcarsAI | 9/6/2026 | 23/7/2026 | A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. | |
| Aplazada | Alta (8.1) | 0.35% | — | BookcarsAI | 9/6/2026 | 23/7/2026 | Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type. | |
| Aplazada | Alta (7.1) | 0.21% | — | Scriptsbundle CarspotAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarSpot carspot allows Reflected XSS.This issue affects CarSpot: from n/a through < 2.4.6. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Axiomthemes Cars4rentAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue affects Cars4Rent: from n/a through <= 1.4.2. | |
| Aplazada | Media (5.9) | 0.14% | — | Lotus CarsAIGoogle AndroidAI | 14/8/2025 | 5/7/2026 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on rooted or debug-enabled devices. This presents a risk of user data exposure. | |
| Aplazada | Media (6.5) | 0.33% | — | Lotus Cars Android APPAI | 14/8/2025 | 5/7/2026 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse. | |
| Analizada | Crítica (9.8) | 0.49% | — | Carspot Project Carspot | 18/2/2025 | 17/6/2026 | The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.26% | — | Dimitar A MY Favorite CarsAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitar A. My Favorite Car my-favorite-cars allows Reflected XSS.This issue affects My Favorite Car: from n/a through <= 1.0. | |
| Modificada | Media (5.3) | 0.36% | — | Hitout Carsale | 2/7/2024 | 17/6/2026 | A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (5.4) | 0.47% | — | Invernyx Smartcars 3 | 26/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the body of news article. | |
| Modificada | Alta (7.5) | 0.36% | — | Invernyx Smartcars 3 | 24/3/2023 | 17/6/2026 | smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in correctly. | |
| Modificada | Crítica (9.8) | 15% | — | Cars-seller-auto-classifieds-script Project Cars-seller-auto-classifieds-script | 14/5/2021 | 17/6/2026 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue. | |
| Modificada | Media (6.1) | 0.64% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | |
| Modificada | Alta (8.8) | 1.2% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database. | |
| Modificada | Alta (8.8) | 1.2% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database. | |
| Modificada | Media (6.1) | 0.64% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | |
| Modificada | Media (5.4) | 0.74% | — | Scriptsbundle Carspot | 3/9/2019 | 17/6/2026 | The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field. | |
| Modificada | Crítica (9.8) | 2.6% | — | Easycarscript | 24/1/2018 | 17/6/2026 | SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php. | |
| Modificada | Media (5.4) | 0.27% | — | Mitsubishicars Mitsubishi Road Assist | 20/10/2014 | 17/6/2026 | The Mitsubishi Road Assist (aka com.agero.mitsubishi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Magzter HOT Cars | 19/10/2014 | 17/6/2026 | The HOT CARS (aka com.magzter.hotcars) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 0.99% | — | T-dreams Cars ADS Package | 24/8/2011 | 16/6/2026 | SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers to execute arbitrary SQL commands via the key parameter. |