Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.48% | — | Themagnifico52 Kids Online StoreAI | 16/6/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9. | |
| Aplazada | Alta (8.8) | 0.33% | — | Online Store System CMSAI | 26/3/2026 | 17/6/2026 | Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind… | |
| Analizada | Media (5.5) | 7.3% | — | Tosei-corporation Online Store Management System | 22/2/2026 | 17/6/2026 | A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file /cgi-bin/monitor.php of the component HTTP POST Request Handler. Performing a manipulation of the argument DevId results in os command injection. The attack may be initiated… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Themerex Sound Musical Instruments Online StoreAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9. | |
| Analizada | Media (5.5) | 6.9% | — | Tosei-corporation Online Store Management System | 19/1/2026 | 17/6/2026 | A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of the file /cgi-bin/imode_alldata.php. Executing a manipulation of the argument DevId can lead to command injection. The attack can be executed remotely. The exploit has been publicly… | |
| Analizada | Media (5.5) | 0.51% | — | Campcodes Retro Basketball Shoes Online Store | 11/12/2025 | 17/6/2026 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Modificada | Baja (2) | 0.34% | — | Campcodes Retro Basketball Shoes Online Store | 8/12/2025 | 17/6/2026 | A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Baja (2) | 0.34% | — | Campcodes Retro Basketball Shoes Online Store | 20/11/2025 | 17/6/2026 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and… | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit… | |
| Modificada | Baja (2) | 0.36% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely.… | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Modificada | Media (5.5) | 0.46% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the… | |
| Modificada | Media (5.5) | 0.46% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument pid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may… | |
| Analizada | Media (5.5) | 0.46% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and… | |
| Aplazada | Alta (7.5) | 0.90% | — | Tosei-corporation Online Store Management SystemAI | 21/8/2024 | 17/6/2026 | An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory traversal. | |
| Modificada | Media (6.9) | 0.55% | — | Tosei-corporation Online Store Management System | 17/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This vulnerability affects unknown code of the component Backend. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.3) | 2.6% | — | Tosei-corporation Online Store Management System | 17/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This affects an unknown part of the file /cgi-bin/tosei_kikai.php. The manipulation of the argument kikaibangou leads to command injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (5.3) | 2.3% | — | Tosei-corporation Online Store Management System | 17/8/2024 | 17/6/2026 | A vulnerability was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cgi-bin/p1_ftpserver.php. The manipulation of the argument adr_txt leads to command injection. The attack may be launched… | |
| Analizada | Media (6.1) | 0.43% | — | Oretnom23 Cosmetics AND Beauty Product Online Store | 15/4/2024 | 17/6/2026 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter. | |
| Analizada | Media (6.1) | 0.43% | — | Oretnom23 Cosmetics AND Beauty Product Online Store | 15/4/2024 | 17/6/2026 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter. | |
| Analizada | Crítica (9.6) | 0.77% | — | Oretnom23 Cosmetics AND Beauty Product Online Store | 15/4/2024 | 17/6/2026 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter. | |
| Analizada | Media (5.4) | 0.41% | — | Oretnom23 Cosmetics AND Beauty Product Online Store | 15/4/2024 | 17/6/2026 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Retro Cellphone Online Store Project Retro Cellphone Online Store | 15/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Retro Cellphone Online Store 1.0. This vulnerability affects unknown code of the file /admin/modal_add_product.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.52% | — | Retro Cellphone Online Store Project Retro Cellphone Online Store | 13/7/2023 | 17/6/2026 | A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add_user_modal.php. The manipulation of the argument un leads to cross site scripting. The attack may be launched remotely. The exploit has been… |