Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.63% | — | Simple-e-commerce-shopping-cart Project Simple-e-commerce-shopping-cart | 13/9/2021 | 17/6/2026 | The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged… | |
| Modificada | Crítica (9.8) | 2.0% | — | Ingenesis Shopp | 13/9/2021 | 17/6/2026 | The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary files and leading to RCE | |
| Modificada | Alta (8.8) | 0.64% | — | Wpeasycart Shopping Cart & Ecommerce Store | 19/8/2021 | 17/6/2026 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0. | |
| Modificada | Crítica (9.1) | 5.2% | 💥 Exploit | Peel Shopping | 30/7/2021 | 17/6/2026 | PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data. | |
| Modificada | Crítica (9.8) | 2.8% | — | Basic Shopping Cart Project Basic Shopping Cart | 30/7/2021 | 17/6/2026 | A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin. | |
| Modificada | Alta (7.5) | 2.1% | — | Online Shopping Alphaware Project Online Shopping Alphaware | 2/6/2021 | 17/6/2026 | The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases. | |
| Modificada | Media (5.4) | 1.6% | 💥 PoC | Peel Shopping | 12/2/2021 | 17/6/2026 | A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect… | |
| Modificada | Crítica (9.8) | 3.3% | — | Online Shopping Alphaware Project Online Shopping Alphaware | 17/8/2020 | 17/6/2026 | A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters. | |
| Modificada | Media (6.5) | 0.43% | — | Peel Shopping | 9/1/2020 | 17/6/2026 | Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Shoppette | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Alta (7.2) | 1.9% | — | Firestormplugins Fs-shopping-cart | 13/9/2019 | 17/6/2026 | The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. | |
| Modificada | Alta (8.8) | 0.85% | — | Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart | 12/9/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.82% | — | Peel Shopping | 30/6/2019 | 17/6/2026 | Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter. | |
| Modificada | Media (4.8) | 0.67% | — | Peel Shopping | 28/12/2018 | 17/6/2026 | Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account. | |
| Modificada | Media (5.9) | 0.52% | — | Shein-fashion Shopping Online | 12/7/2018 | 17/6/2026 | The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 29/12/2017 | 17/6/2026 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism." | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the… | |
| Modificada | Media (4) | 9.1% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to… | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,… | |
| Modificada | Media (5.4) | 0.27% | — | Mbtcreations Atkins Diet Free Shopping List | 21/10/2014 | 17/6/2026 | The Atkins Diet Free Shopping List (aka com.wAtkinsDietFreeShoppingList) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Myfone Shopping | 21/10/2014 | 17/6/2026 | The myfone Shopping (aka com.twm.pt.eccart) application 2.1.01.00.040 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Kalahari.com Shopping | 2/10/2014 | 17/6/2026 | The kalahari.com Shopping (aka com.kalahari.shop) application 1.4.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Covetfashion Covet Fashion - Shopping Game | 30/9/2014 | 17/6/2026 | The Covet Fashion - Shopping Game (aka com.crowdstar.covetfashion) application 2.14.40 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Grasshopper Beta | 28/9/2014 | 17/6/2026 | The Grasshopper Beta (aka com.grasshopper.dialer) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Miniinthebox Online Shopping | 15/9/2014 | 17/6/2026 | The MiniInTheBox Online Shopping (aka com.miniinthebox.android) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |