Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | — | Wpshopstyling Wp-ecommerce-shop-styling | 27/5/2014 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter. | |
| Modificada | Media (4) | 1.3% | — | Spreecommerce Spree | 8/3/2013 | 16/6/2026 | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves. | |
| Modificada | Media (4.3) | 1.5% | — | Spreecommerce Spree | 8/3/2013 | 16/6/2026 | Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and the (2) promotion_action parameter to… | |
| Modificada | Alta (7.5) | 1.3% | — | Neturf Ecommerce Shopping Cart | 23/9/2012 | 16/6/2026 | SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Totalshopuk Ecommerce | 20/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Source before 2.1.2_p1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Media (5) | 1.2% | — | Spreecommerce Spree | 5/4/2012 | 16/6/2026 | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file. | |
| Modificada | Media (5) | 1.2% | — | Spreecommerce Spree | 5/4/2012 | 16/6/2026 | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Ecommercemax Digital-goods Seller | 16/2/2011 | 16/6/2026 | SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote attackers to execute arbitrary SQL commands via the d parameter. | |
| Modificada | Media (5) | 2.5% | — | Spreecommerce Spree | 17/11/2010 | 16/6/2026 | Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3)… | |
| Modificada | Media (4.3) | 1.1% | — | Ecommercesoft XSE Shopping Cart | 17/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bazaarbuilder Ecommerce Shopping Cart | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Razorecommerce Shopping Cart | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Comdev Ecommerce | 6/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Edit-x Ecommerce | 12/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Cutting Edge Computing Edge Ecommerce Shop | 22/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge eCommerce Shop allows remote attackers to inject arbitrary web script or HTML via the cart_id parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Totalecommerce | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Digital Builder NZ Ecommerce | 9/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a… | |
| Modificada | Media (4.3) | 1.3% | — | Digital Builder NZ Ecommerce | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem | |
| Modificada | Alta (10) | 1.7% | — | Intensive Point Iuser Ecommerce | 24/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (from January 8, 2005) is too vague to be sure, and CVE-2006-0854… | |
| Modificada | Alta (7.5) | 2.1% | — | Intensive Point Iuser Ecommerce | 23/2/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Web4future Ecommerce Enterprise EditionAI | 6/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php. | |
| Modificada | Media (5) | 1.5% | — | Comdev Ecommerce | 10/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Comdev Ecommerce | 10/8/2005 | 16/6/2026 | Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter. | |
| Modificada | Media (4.3) | 0.99% | — | Comdev Ecommerce | 5/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Early Impact Productcart Ecommerce | 16/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp. |