Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress… | |
| Aplazada | Alta (8.5) | 0.30% | — | Go-shioriAI | 5/8/2026 | 26/8/2026 | go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks). | |
| Aplazada | Alta (8.3) | 0.37% | — | Go-shiori ShioriAI | 5/8/2026 | 26/8/2026 | Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. | |
| Aplazada | Alta (8.7) | 0.52% | — | Go-shiori ShioriAI | 13/7/2026 | 13/7/2026 | Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with owner: true, then re-authenticate to obtain an admin JWT token… | |
| Aplazada | Alta (7.5) | 0.43% | — | Pavothemes FreshioAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Freshio freshio allows PHP Local File Inclusion.This issue affects Freshio: from n/a through <= 2.4.2. | |
| Analizada | Media (6.5) | 0.41% | — | Go-shiori Shiori | 9/1/2026 | 17/6/2026 | A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack. | |
| Aplazada | Alta (7.5) | 0.45% | — | Opal WP FashionAIPHPAI | 9/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Opal_WP Fashion fashion2 allows PHP Local File Inclusion.This issue affects Fashion: from n/a through < 5.3.0. | |
| Aplazada | Media (6.4) | 0.18% | — | Angel Fashion Model AgencyAI | 13/11/2025 | 17/6/2026 | The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting the profile media uploader in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2.1) | 0.36% | — | Viglet Shio | 31/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the… | |
| Analizada | Baja (2.1) | 0.88% | — | Viglet Shio | 31/7/2025 | 17/6/2026 | A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. The attack may be… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Themeton THE Fashion - Model Agency ONE Page Beauty ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This issue affects The Fashion - Model Agency One Page Beauty Theme: from n/a through <= 1.4.4. | |
| Modificada | Media (6.1) | 1.0% | — | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Crítica (9.3) | 1.3% | — | Kg-fashion-chatbot Project Kg-fashion-chatbot | 11/7/2022 | 17/6/2026 | The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (5.9) | 0.52% | — | Shein-fashion Shopping Online | 12/7/2018 | 17/6/2026 | The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Teamlava Fashion Story\ | 19/10/2014 | 17/6/2026 | The Fashion Story: Neon 90's (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Tabtale Enchanted Fashion Crush | 19/10/2014 | 17/6/2026 | The Enchanted Fashion Crush (aka com.tabtale.springcrushbundleint) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Covetfashion Covet Fashion - Shopping Game | 30/9/2014 | 17/6/2026 | The Covet Fashion - Shopping Game (aka com.crowdstar.covetfashion) application 2.14.40 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Threadflip BUY Sell Fashion | 22/9/2014 | 17/6/2026 | The Threadflip : Buy, Sell Fashion (aka com.threadflip.android) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Animoca Fashion Style | 9/9/2014 | 17/6/2026 | The Fashion Style (aka com.thirtysixyougames.google.starGirlSingapore) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |