Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)0.37%—Smart ManagerAI3/10/20263/10/2026
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaMedia (4.8)0.24%—Smart ManagerAI27/7/202627/7/2026
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
AplazadaAlta (7.1)0.25%—Smart ManagerAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
AplazadaAlta (8.8)0.42%—Storeapps Smart ManagerAI25/5/202624/7/2026
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.
AplazadaAlta (7.6)0.83%—Storeapps Smart Manager FOR WP E CommerceAI21/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
AplazadaMedia (4.3)0.29%—Storeapps Smart Manager FOR WP E CommerceAI31/12/202417/6/2026
Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0.
ModificadaAlta (7.2)3.3%—Storeapps Smart Manager12/2/202417/6/2026
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
ModificadaAlta (7.1)0.22%—Samsung Smart Manager11/6/202117/6/2026
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.