Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Ecommerce-carts Ecommpro | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field. | |
| Rechazada | Sin puntuar | — | 💥 Exploit | LitecommerceAI | 6/4/2005 | 7/11/2023 | Rejected reason: cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters. NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type… | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Netsourcecommerce Productcart | 31/12/2004 | 16/6/2026 | EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack. | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Ecommerce Corporation Online Store KIT | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | |
| Modificada | Alta (10) | 5.2% | 💥 Exploit | Ecommerce Corporation Online Store KIT | 23/11/2004 | 16/6/2026 | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php. | |
| Modificada | Media (5) | 2.0% | — | MDG Computer Services WEB Server 4D Ecommerce | 25/3/2002 | 16/6/2026 | MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request. | |
| Modificada | Alta (7.5) | 3.3% | — | MDG Computer Services WEB Server 4D Ecommerce | 25/3/2002 | 16/6/2026 | MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. |