Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%—Wpshopstyling Wp-ecommerce-shop-styling27/5/201416/6/2026
PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter.
ModificadaMedia (4)1.3%—Spreecommerce Spree8/3/201316/6/2026
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
ModificadaMedia (4.3)1.5%—Spreecommerce Spree8/3/201316/6/2026
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and the (2) promotion_action parameter to…
ModificadaAlta (7.5)1.3%—Neturf Ecommerce Shopping Cart23/9/201216/6/2026
SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.6%💥 ExploitTotalshopuk Ecommerce20/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaMedia (5)1.2%—Spreecommerce Spree5/4/201216/6/2026
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.
ModificadaMedia (5)1.2%—Spreecommerce Spree5/4/201216/6/2026
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.
ModificadaAlta (7.5)0.99%💥 ExploitEcommercemax Digital-goods Seller16/2/201116/6/2026
SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote attackers to execute arbitrary SQL commands via the d parameter.
ModificadaMedia (5)2.5%—Spreecommerce Spree17/11/201016/6/2026
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3)…
ModificadaMedia (4.3)1.1%—Ecommercesoft XSE Shopping Cart17/9/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.
ModificadaAlta (7.5)0.99%💥 ExploitBazaarbuilder Ecommerce Shopping Cart2/2/200916/6/2026
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.
ModificadaAlta (7.5)1.1%—Razorecommerce Shopping Cart24/9/200816/6/2026
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.4%—Comdev Ecommerce6/6/200716/6/2026
PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.
ModificadaAlta (7.5)2.7%💥 ExploitEdit-x Ecommerce12/1/200716/6/2026
PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.
ModificadaMedia (4.3)1.2%—Cutting Edge Computing Edge Ecommerce Shop22/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge eCommerce Shop allows remote attackers to inject arbitrary web script or HTML via the cart_id parameter.
ModificadaAlta (7.5)1.3%💥 ExploitTotalecommerce9/3/200616/6/2026
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.
ModificadaAlta (7.5)1.1%💥 ExploitDigital Builder NZ Ecommerce9/3/200616/6/2026
Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a…
ModificadaMedia (4.3)1.3%—Digital Builder NZ Ecommerce9/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem
ModificadaAlta (10)1.7%—Intensive Point Iuser Ecommerce24/2/200616/6/2026
Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (from January 8, 2005) is too vague to be sure, and CVE-2006-0854…
ModificadaAlta (7.5)2.1%—Intensive Point Iuser Ecommerce23/2/200616/6/2026
PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used.
ModificadaAlta (7.5)1.3%💥 ExploitWeb4future Ecommerce Enterprise EditionAI6/12/200516/6/2026
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
ModificadaMedia (5)1.5%—Comdev Ecommerce10/8/200516/6/2026
PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.
ModificadaMedia (5)6.0%💥 ExploitComdev Ecommerce10/8/200516/6/2026
Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.
ModificadaMedia (4.3)0.99%—Comdev Ecommerce5/7/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.
ModificadaAlta (7.5)1.1%💥 ExploitEarly Impact Productcart Ecommerce16/6/200516/6/2026
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
Orbitaley — Vulnerabilidades