Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.53%—BookcarsAI9/6/202623/7/2026
An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
AplazadaMedia (5.3)0.69%—BookcarsAI9/6/202623/7/2026
An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences.
AplazadaAlta (8.8)1.4%—BookcarsAI9/6/202623/7/2026
An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbitrary locations on the server filesystem. This enables unauthorized access to sensitive files, the…
AplazadaMedia (5.4)0.30%—BookcarsAI9/6/202623/7/2026
An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.
AplazadaCrítica (9.8)0.40%—BookcarsAI9/6/202623/7/2026
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
AplazadaAlta (8.1)0.35%—BookcarsAI9/6/202623/7/2026
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.
AplazadaAlta (7.1)0.21%—Scriptsbundle CarspotAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarSpot carspot allows Reflected XSS.This issue affects CarSpot: from n/a through < 2.4.6.
AplazadaCrítica (9.8)0.50%—Axiomthemes Cars4rentAI20/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue affects Cars4Rent: from n/a through <= 1.4.2.
AplazadaMedia (5.9)0.14%—Lotus CarsAIGoogle AndroidAI14/8/20255/7/2026
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on rooted or debug-enabled devices. This presents a risk of user data exposure.
AplazadaMedia (6.5)0.33%—Lotus Cars Android APPAI14/8/20255/7/2026
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.
AnalizadaCrítica (9.8)0.49%—Carspot Project Carspot18/2/202517/6/2026
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated…
AplazadaAlta (7.1)0.26%—Dimitar A MY Favorite CarsAI23/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitar A. My Favorite Car my-favorite-cars allows Reflected XSS.This issue affects My Favorite Car: from n/a through <= 1.0.
ModificadaMedia (5.3)0.36%—Hitout Carsale2/7/202417/6/2026
A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (5.4)0.47%—Invernyx Smartcars 326/5/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the body of news article.
ModificadaAlta (7.5)0.36%—Invernyx Smartcars 324/3/202317/6/2026
smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in correctly.
ModificadaCrítica (9.8)15%—Cars-seller-auto-classifieds-script Project Cars-seller-auto-classifieds-script14/5/202117/6/2026
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.
ModificadaMedia (6.1)0.64%—Carson-saint Saint Security Suite10/8/202017/6/2026
A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
ModificadaAlta (8.8)1.2%—Carson-saint Saint Security Suite10/8/202017/6/2026
An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.
ModificadaAlta (8.8)1.2%—Carson-saint Saint Security Suite10/8/202017/6/2026
An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.
ModificadaMedia (6.1)0.64%—Carson-saint Saint Security Suite10/8/202017/6/2026
A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
ModificadaMedia (5.4)0.74%—Scriptsbundle Carspot3/9/201917/6/2026
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
ModificadaCrítica (9.8)2.6%—Easycarscript24/1/201817/6/2026
SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.
ModificadaMedia (5.4)0.27%—Mitsubishicars Mitsubishi Road Assist20/10/201417/6/2026
The Mitsubishi Road Assist (aka com.agero.mitsubishi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.29%—Magzter HOT Cars19/10/201417/6/2026
The HOT CARS (aka com.magzter.hotcars) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)0.99%—T-dreams Cars ADS Package24/8/201116/6/2026
SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.