Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

364 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.99%💥 ExploitResalecode PHP Shopping Cart Selling Website Script10/3/201016/6/2026
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (4.3)3.1%💥 ExploitResalecode PHP Shopping Cart Selling Website Script10/3/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.
ModificadaMedia (4.3)1.2%—Pentasoft Corp. Avactis Shopping Cart13/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) step_id and (2) CHECKOUT_CZ_BLOWFISH_KEY parameters.
ModificadaAlta (7.5)1.0%💥 ExploitVirtuenetz Virtue Shopping Mall9/6/200916/6/2026
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (6.8)3.5%💥 ExploitE-cart Free Shopping Cart27/4/200916/6/2026
Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.
ModificadaMedia (4.3)1.4%💥 ExploitCodetoad ASP Shopping Cart Script20/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
ModificadaAlta (7.8)2.5%💥 ExploitRakhisoftware Shopping Cart25/2/200916/6/2026
RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.
ModificadaMedia (4.3)1.5%💥 ExploitRakhisoftware Shopping Cart25/2/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.
ModificadaAlta (7.5)1.0%💥 ExploitRakhisoftware Shopping Cart25/2/200916/6/2026
SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.
ModificadaAlta (7.5)2.9%💥 ExploitPreprojects PRE Shopping Mall20/2/200916/6/2026
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".
ModificadaAlta (7.5)2.7%💥 ExploitPreproject PRE Multi-vendor Shopping Malls20/2/200916/6/2026
Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".
ModificadaAlta (7.5)0.97%💥 ExploitPreproject PRE Multi-vendor Shopping Malls20/2/200916/6/2026
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters.
ModificadaAlta (7.5)0.97%💥 ExploitSepcity Shopping Mall16/2/200916/6/2026
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)1.5%—Interspire Shopping Cart3/2/200916/6/2026
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.
ModificadaAlta (7.5)0.99%💥 ExploitBazaarbuilder Ecommerce Shopping Cart2/2/200916/6/2026
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.
ModificadaMedia (5)2.6%💥 ExploitVpasp Vp-asp Shopping Cart21/1/200916/6/2026
VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the password via a direct request for database/shopping650.mdb. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitEphpscripts E-shop Shopping Cart5/1/200916/6/2026
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)2.4%💥 ExploitYourfreeworld Shopping Cart Script4/11/200816/6/2026
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.
ModificadaAlta (7.5)1.1%—Razorecommerce Shopping Cart24/9/200816/6/2026
SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.6%💥 ExploitTurnkeywebtools Sunshop Shopping Cart22/8/200816/6/2026
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors.
ModificadaAlta (7.5)0.97%💥 ExploitPozscripts Greencart PHP Shopping Cart11/8/200816/6/2026
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php.
ModificadaAlta (7.5)1.0%💥 ExploitCartkeeper Ckgold Shopping Cart19/6/200816/6/2026
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.
ModificadaAlta (7.5)1.0%💥 ExploitTurnkeywebtools Sunshop Shopping Cart19/5/200816/6/2026
SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Shopping Mall8/5/200816/6/2026
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaMedia (6.5)0.89%—Turnkey Solutions Sunshop Shopping Cart30/4/200816/6/2026
Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely…
Orbitaley — Vulnerabilidades