Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.30%—Sunshinephotocart Sunshine Photo CartAI9/9/20269/9/2026
The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in…
AplazadaAlta (7.5)0.41%—Sunshinephotocart Sunshine Photo CartAI5/8/202626/8/2026
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
AplazadaMedia (6.3)0.26%—Sunshine Systems Photo CartAI23/7/202623/7/2026
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
AplazadaMedia (6.3)0.26%—Sunshinephotocart Sunshine Photo CartAI25/5/202624/7/2026
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.
AnalizadaCrítica (9.8)0.43%—Lizardbyte Sunshine22/5/202623/7/2026
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY,…
AplazadaMedia (5.3)0.33%—Sunshinephotocart Sunshine Photo CartAI8/4/202624/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2.
AplazadaMedia (6.5)0.24%—Sunshinephotocart Sunshine Photo CartAI20/2/202617/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2.
AplazadaMedia (5.3)0.20%—Sunshinephotocart Sunshine Photo CartAI3/2/202617/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2.
AplazadaMedia (4.3)0.19%—Sunshinephotocart Sunshine Photo CartAI24/12/202517/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1.
AplazadaMedia (5.3)0.27%—Sunshinephotocart Sunshine Photo CartAI27/10/202517/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.
AnalizadaAlta (7)0.23%—Lizardbyte Sunshine23/9/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may…
ModificadaAlta (7.8)0.19%—Lizardbyte Sunshine9/9/202517/6/2026
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
ModificadaAlta (7.8)0.22%—Lizardbyte Sunshine9/9/202517/6/2026
Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.
AplazadaMedia (5.4)0.24%—Cyclonedx SunshineAI13/8/202517/6/2026
CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file
AnalizadaMedia (6.1)0.22%—Lizardbyte Sunshine1/7/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked…
AnalizadaAlta (8.8)0.23%—Lizardbyte Sunshine1/7/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended…
AnalizadaAlta (8.8)0.56%—Sunshinephotocart Sunshine Photo Cart4/6/202517/6/2026
The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes it possible for authenticated attackers,…
ModificadaCrítica (9.8)0.70%—Sunshinephotocart Sunshine Photo Cart1/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10.
AnalizadaAlta (7.7)0.58%—Lizardbyte Sunshine20/1/202517/6/2026
Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing attempt. This bug…
AnalizadaMedia (5.4)0.43%—Sunshinephotocart Sunshine Photo Cart13/12/202417/6/2026
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.
ModificadaMedia (4.3)0.41%—Sunshinephotocart Sunshine Photo Cart19/11/202417/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9.
ModificadaAlta (8.8)0.39%—Sunshinephotocart Sunshine Photo Cart1/11/202417/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.8.
ModificadaCrítica (9.8)0.41%—Sunshinephotocart Sunshine Photo Cart1/11/202417/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9.
ModificadaAlta (8.8)0.44%—Sunshinephotocart Sunshine Photo Cart1/11/202417/6/2026
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.1.
ModificadaMedia (6.1)0.26%—Sunshinephotocart Sunshine Photo Cart28/10/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9.