Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Home Shopping Apps BUY A Gift | 9/9/2014 | 17/6/2026 | The Buy A Gift (aka com.wBuyAGift) application 13529.90084 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Pointinside Point Inside Shopping & Travel | 9/9/2014 | 17/6/2026 | The Point Inside Shopping & Travel (aka com.pointinside.android.app) application 3.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Appministry Princess Shopping | 9/9/2014 | 17/6/2026 | The Princess Shopping (aka air.android.PrincessShopping) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.1% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 13/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings. | |
| Modificada | Media (4.3) | 1.1% | — | Maxxmarketing Joomshopping | 11/2/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the user_name parameter to index.php. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Uaepd Shopping Cart Script | 21/1/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php. | |
| Modificada | Media (5.8) | 0.52% | — | Yahoo Japan Shopping | 21/8/2013 | 16/6/2026 | The Yahoo! Japan Shopping application 1.4 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.1% | — | Getshopped WP E-commerce | 8/10/2012 | 16/6/2026 | SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Peel Shopping | 1/10/2012 | 16/6/2026 | SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Peel Shopping | 1/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Neturf Ecommerce Shopping Cart | 23/9/2012 | 16/6/2026 | SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 2.2% | — | Getshopped WP E-commerce | 23/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Atmarkweb @web Shoppingcart TAtmarkweb @web Shoppingcart | 15/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WEBLOGIC @WEB ShoppingCart before 1.5.2.0, and @WEB ShoppingCart T 1.5.0.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | BST Bestshoppro | 14/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web script or HTML via the str parameter. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | BST Bestshoppro | 14/12/2011 | 16/6/2026 | SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Virtuenetz Virtue Shopping Mall | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Avactis Shopping Cart | 2/11/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php. | |
| Modificada | Media (4.3) | 1.1% | — | Ecommercesoft XSE Shopping Cart | 17/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phpscripte24 Live Shopping Multi Portal System | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajsquare AJ Shopping Cart | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Ecomstudio PHP Easy Shopping Cart | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (4.3) | 0.88% | — | Vpasp Vp-asp Shopping Cart | 28/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and… | |
| Modificada | Media (5) | 1.6% | — | Vpasp Vp-asp Shopping Cart | 28/4/2010 | 16/6/2026 | Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the… | |
| Modificada | Alta (7.5) | 1.1% | — | Vpasp Vp-asp Shopping Cart | 28/4/2010 | 16/6/2026 | SQL injection vulnerability in the Getwebsess function in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via the websess parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Resalecode PHP Shopping Cart Selling Website Script | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. |