Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.27%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of…
AnalizadaBaja (3.3)0.14%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service…
AplazadaAlta (8.6)1.6%—8theme XstoreAI10/6/202623/7/2026
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
AplazadaAlta (7.1)0.18%—8theme Xstore CoreAI8theme Et-core-pluginAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4.
AplazadaMedia (6.5)0.17%—8theme Xstore CoreAI19/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7.
AplazadaMedia (6.5)0.17%—8theme XstoreAI19/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through <= 9.6.4.
AplazadaMedia (5.3)0.24%—8theme XstoreAI19/2/202617/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4.
AplazadaMedia (6.5)0.16%—8theme Xstore CoreAI30/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6.
AplazadaAlta (7.5)0.46%—8theme XstoreAI18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in 8theme XStore xstore allows PHP Local File Inclusion.This issue affects XStore: from n/a through < 9.6.1.
AplazadaAlta (7.1)0.22%—8theme XstoreAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows Reflected XSS.This issue affects XStore: from n/a through < 9.6.1.
AplazadaAlta (7.1)0.22%—8theme Xstore CoreAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through < 5.6.
AplazadaMedia (6.3)0.22%—8theme XstoreAI18/12/20251/10/2026
Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects XStore: from n/a through < 9.6.
AplazadaAlta (8.8)0.72%—8theme XstoreAI15/10/202517/6/2026
The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server,…
AplazadaMedia (5.3)0.29%—8theme XstoreAI26/9/202517/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through < 9.6.
AnalizadaAlta (8.6)1.8%—Oracle Retail Xstore Office16/7/202417/6/2026
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail…
ModificadaMedia (4.3)0.32%—8theme Xstore9/6/202417/6/2026
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
ModificadaAlta (8.8)0.35%—8theme Xstore9/6/202417/6/2026
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
ModificadaCrítica (9.8)0.43%—8theme Xstore9/6/202417/6/2026
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
ModificadaAlta (8.8)0.42%—8theme Xstore Core9/6/202417/6/2026
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
AplazadaCrítica (9)0.60%—8theme XstoreAI4/6/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: from n/a through 9.3.8.
AnalizadaAlta (8.8)0.56%—8theme Xstore Core4/6/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
AnalizadaCrítica (9.8)0.57%—8theme Xstore Core17/5/202417/6/2026
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
AnalizadaCrítica (9.8)0.58%—8theme Xstore Core17/5/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
ModificadaMedia (6.5)0.43%—8theme Xstore Core29/4/202417/6/2026
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
ModificadaCrítica (9.8)0.58%—8theme Xstore Core29/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.