Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.59% | — | Xerox Xmpie Ustore | 10/2/2022 | 9/7/2026 | A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0. | |
| Modificada | Alta (7.5) | 1.6% | — | Xerox Xmpie Ustore | 7/2/2022 | 9/7/2026 | XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database. | |
| Modificada | Media (6.9) | 0.32% | — | Eucalyptus Eustore | 17/9/2013 | 16/6/2026 | Eucalyptus EuStore sets a blank root password in the default configuration of EMI 3868652036, EMI 0400376721, EMI 2425352071, and EMI 1347115203, which allows local users to gain privileges via unspecified vectors, a related issue to CVE-2013-2069. | |
| Modificada | Alta (7.5) | 1.3% | — | Superfreaker Studios Ustore | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Dynamic Dataworx Nustore | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Xmpie Ustore | 20/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in UStore allow remote attackers to inject arbitrary web script or HTML via the (1) Cat parameter in default.asp and the (2) accessdenied parameter in admin/default.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (7.5) | 1.2% | — | Xmpie Ustore | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in UStore allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 6.5% | — | Microburst Ustorekeeper Online Shopping System | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. |