Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.41%—Infor Storefront B2BAI30/1/202617/6/2026
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database…
AplazadaAlta (7.1)0.13%—Dactum Clickbank Niche StorefrontsAI28/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) clickbank-niche-storefronts allows Stored XSS.This issue affects Clickbank WordPress Plugin (Niche Storefront): from n/a through <= 1.3.5.
AnalizadaMedia (4.3)0.29%—Vwthemes VW Storefront4/3/202517/6/2026
The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset…
AnalizadaCrítica (9)0.62%—Selldone Storefront3/3/202517/6/2026
Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
AplazadaAlta (7.1)0.37%—Dactum Clickbank StorefrontAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dactum ClickBank Storefront mycbgenie-clickbank-storefront allows Reflected XSS.This issue affects ClickBank Storefront: from n/a through <= 1.7.
AplazadaMedia (6.1)0.15%—Clickbank StorefrontAI6/12/202417/6/2026
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious…
AnalizadaMedia (6.5)0.57%—Saleor React-storefront20/3/202417/6/2026
Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version…
ModificadaMedia (6.1)73%—Cloud Citrix Storefront17/1/202417/6/2026
Cross-site scripting (XSS)
ModificadaMedia (6.1)0.46%—Saleor React-storefront16/6/202317/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
ModificadaMedia (6.1)0.48%—Citrix Storefront Server13/4/202217/6/2026
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
ModificadaMedia (4.8)0.62%—Wooassist Storefront Footer Text8/11/202117/6/2026
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
ModificadaAlta (7.5)1.1%—Epignosishq Efront3/3/202117/6/2026
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their…
ModificadaMedia (6.5)1.3%—Citrix Storefront Server18/9/202017/6/2026
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
ModificadaAlta (7.1)0.72%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection14/7/202017/6/2026
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
ModificadaAlta (7.8)1.6%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection9/6/202017/6/2026
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
ModificadaAlta (7.8)0.89%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection9/6/202017/6/2026
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170.
ModificadaMedia (5.3)15%—Divante Storefront-apiDivante Vue-storefront-api17/4/202017/6/2026
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
ModificadaAlta (7.1)0.71%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection15/4/202017/6/2026
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
ModificadaMedia (6.1)0.81%—Mediawiki Mobilefrontend19/3/202017/6/2026
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33.
ModificadaAlta (7.5)4.1%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection23/9/201917/6/2026
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.
ModificadaMedia (6.5)1.0%—Epignosishq Efront LMS5/9/201917/6/2026
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are…
ModificadaAlta (8.8)2.3%—Epignosishq Efront LMS5/9/201917/6/2026
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
AnalizadaAlta (7.5)30%⚠ Explotación activaCitrix Storefront Server29/8/201917/6/2026
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
ModificadaAlta (7.1)0.90%—Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection14/8/201917/6/2026
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete…
ModificadaMedia (6.1)0.70%—Mediawiki Mobilefrontend9/8/201917/6/2026
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.