Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.47% | — | Exrick XmallAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the… | |
| Analizada | Alta (8.2) | 0.23% | — | Exrick Xmall | 12/1/2026 | 17/6/2026 | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId. | |
| Analizada | Media (6.1) | 0.18% | — | Exrick Xmall | 29/11/2025 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scripts. | |
| Analizada | Crítica (9.8) | 0.54% | — | Exrick Xmall | 5/5/2025 | 17/6/2026 | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. | |
| Analizada | Crítica (9.8) | 0.61% | — | Exrick Xmall | 15/4/2025 | 17/6/2026 | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | |
| Modificada | Crítica (9.8) | 3.3% | — | Exrick Xmall | 6/2/2024 | 17/6/2026 | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Exrick Xmall | 7/4/2022 | 9/7/2026 | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. |