Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Sunshinephotocart Sunshine Photo CartAI | 9/9/2026 | 9/9/2026 | The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in… | |
| Aplazada | Alta (7.5) | 0.41% | — | Sunshinephotocart Sunshine Photo CartAI | 5/8/2026 | 26/8/2026 | The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries. | |
| Aplazada | Media (6.3) | 0.26% | — | Sunshine Systems Photo CartAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. | |
| Aplazada | Media (6.3) | 0.26% | — | Sunshinephotocart Sunshine Photo CartAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7. | |
| Analizada | Crítica (9.8) | 0.43% | — | Lizardbyte Sunshine | 22/5/2026 | 23/7/2026 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY,… | |
| Aplazada | Media (5.3) | 0.33% | — | Sunshinephotocart Sunshine Photo CartAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2. | |
| Aplazada | Media (6.5) | 0.24% | — | Sunshinephotocart Sunshine Photo CartAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2. | |
| Aplazada | Media (5.3) | 0.20% | — | Sunshinephotocart Sunshine Photo CartAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2. | |
| Aplazada | Media (4.3) | 0.19% | — | Sunshinephotocart Sunshine Photo CartAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1. | |
| Aplazada | Media (5.3) | 0.27% | — | Sunshinephotocart Sunshine Photo CartAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3. | |
| Analizada | Alta (7) | 0.23% | — | Lizardbyte Sunshine | 23/9/2025 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may… | |
| Modificada | Alta (7.8) | 0.19% | — | Lizardbyte Sunshine | 9/9/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path. | |
| Modificada | Alta (7.8) | 0.22% | — | Lizardbyte Sunshine | 9/9/2025 | 17/6/2026 | Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories. | |
| Aplazada | Media (5.4) | 0.24% | — | Cyclonedx SunshineAI | 13/8/2025 | 17/6/2026 | CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file | |
| Analizada | Media (6.1) | 0.22% | — | Lizardbyte Sunshine | 1/7/2025 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked… | |
| Analizada | Alta (8.8) | 0.23% | — | Lizardbyte Sunshine | 1/7/2025 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended… | |
| Analizada | Alta (8.8) | 0.56% | — | Sunshinephotocart Sunshine Photo Cart | 4/6/2025 | 17/6/2026 | The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes it possible for authenticated attackers,… | |
| Modificada | Crítica (9.8) | 0.70% | — | Sunshinephotocart Sunshine Photo Cart | 1/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10. | |
| Analizada | Alta (7.7) | 0.58% | — | Lizardbyte Sunshine | 20/1/2025 | 17/6/2026 | Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing attempt. This bug… | |
| Analizada | Media (5.4) | 0.43% | — | Sunshinephotocart Sunshine Photo Cart | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13. | |
| Modificada | Media (4.3) | 0.41% | — | Sunshinephotocart Sunshine Photo Cart | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. | |
| Modificada | Alta (8.8) | 0.39% | — | Sunshinephotocart Sunshine Photo Cart | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.8. | |
| Modificada | Crítica (9.8) | 0.41% | — | Sunshinephotocart Sunshine Photo Cart | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. | |
| Modificada | Alta (8.8) | 0.44% | — | Sunshinephotocart Sunshine Photo Cart | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.1. | |
| Modificada | Media (6.1) | 0.26% | — | Sunshinephotocart Sunshine Photo Cart | 28/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. |