Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.19% | — | Zenc-lang ZEN C | 26/3/2026 | 17/6/2026 | Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based buffer overflow vulnerability in the Zen C compiler allows attackers to cause a compiler crash or potentially execute arbitrary code by providing a specially crafted Zen C source file (`.zc`) with… | |
| Analizada | Alta (7.3) | 1.1% | — | Zenc-lang ZEN C | 26/2/2026 | 17/6/2026 | Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shell commands by providing a specially crafted output filename via the `-o` command-line argument. The… | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Crítica (9) | 0.81% | — | ZTE Zenic ONE R58 | 30/12/2024 | 17/6/2026 | The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices. | |
| Analizada | Alta (8.1) | 72% | — | Zen-cart ZEN Cart | 21/8/2024 | 17/6/2026 | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability. The specific flaw exists within the findPluginAdminPage… | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Modificada | Media (6.1) | 0.84% | — | Zen-cart ZEN Cart | 19/3/2021 | 17/6/2026 | Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php. | |
| Modificada | Alta (7.2) | 17% | — | Zen-cart ZEN Cart | 26/1/2021 | 17/6/2026 | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command. | |
| Modificada | Media (5.5) | 0.35% | — | ZTE Zenic ONE R22b | 30/4/2020 | 17/6/2026 | ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk. This affects: ZENIC ONE R22b versions V16.19.10P02SP002 and… | |
| Modificada | Crítica (9.8) | 16% | — | Zen-cart ZEN Cart | 24/8/2017 | 17/6/2026 | Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php. | |
| Modificada | Alta (8.8) | 2.9% | — | Zen-cart ZEN Cart | 27/7/2017 | 17/6/2026 | The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of the admin_name array parameter to admin_dir/login.php, if there… | |
| Modificada | Media (6.1) | 0.65% | — | Zen-cart ZEN Cart | 29/6/2017 | 17/6/2026 | In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS. | |
| Modificada | Media (6.1) | 0.68% | — | Zen-cart ZEN Cart | 8/5/2017 | 17/6/2026 | Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github." | |
| Modificada | Media (5.8) | 1.7% | — | Zen-cart ZEN Cart | 24/4/2015 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.php. | |
| Modificada | Media (4.3) | 2.2% | — | Zen-cart ZEN Cart | 27/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja through 1.5.1 ja allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to admin/includes/init_includes/init_sanitize.php and… | |
| Modificada | Media (5.8) | 0.57% | — | Firstdata LinkpointZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Lincolnloop Authorize.net Echeck ModuleZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Payments PROZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP… | |
| Modificada | Media (5.8) | 0.57% | — | Paypal Instant Payment NotificationZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than… | |
| Modificada | Baja (2.6) | 0.84% | — | Zen-cart ZEN Cart | 27/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php. | |
| Modificada | Media (4.3) | 1.5% | — | Zen-cart ZEN Cart | 29/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547. | |
| Modificada | Media (4.3) | 1.1% | — | Zen-cart ZEN Cart | 29/11/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary web script or HTML via the (1) main_page parameter or (2) PATH_INFO, a different vulnerability than… | |
| Modificada | Alta (7.5) | 2.6% | — | Zen-cart ZEN Cart | 14/12/2009 | 16/6/2026 | The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) install.txt, which allows remote attackers to obtain sensitive information, delete the database, and conduct other attacks via a direct request, different vulnerabilities… | |
| Modificada | Media (5) | 1.3% | — | Zen-cart ZEN Cart | 14/12/2009 | 16/6/2026 | extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 2.5% | — | Zen-cart ZEN Cart | 14/12/2009 | 16/6/2026 | extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NOTE: some of these details are obtained from third party information. |