Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
364 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | 5TH Avenue Software 5TH Avenue Shopping Cart | 23/4/2008 | 16/6/2026 | SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Interspire Shopping Cart | 29/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Shoppingtree Candypress Store | 13/2/2008 | 16/6/2026 | SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Shoppingtree Candypress Store | 13/2/2008 | 16/6/2026 | SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Shoppingtree Candypress Store | 13/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp. NOTE: the… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Shoppingtree Candypress Store | 13/2/2008 | 16/6/2026 | admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Shoppingtree Candypress Store | 1/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Shoppingtree Candypress Store | 1/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp. | |
| Modificada | Alta (10) | 2.4% | — | Viart Shopping Cart | 11/10/2007 | 16/6/2026 | Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cartkeeper Ckgold Shopping Cart | 6/9/2007 | 16/6/2026 | SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | |
| Modificada | Media (5) | 1.8% | — | Cgi-rescue Shopping Basket Professional | 4/9/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 30/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549. | |
| Modificada | Alta (10) | 2.2% | — | E-commerce Solutions Auction ScriptE-commerce Solutions Multi-vendor E-shop ScriptE-commerce Solutions Shopping Cart Script | 1/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from… | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected. | |
| Modificada | Alta (7.5) | 1.3% | — | Salescart Shopping Cart | 4/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo… | |
| Modificada | Media (6.8) | 1.7% | — | Vp-asp Shopping Cart | 22/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | PRE Projects PRE Shopping Mall | 14/5/2007 | 16/6/2026 | SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter. | |
| Modificada | Media (6.4) | 1.0% | — | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation." | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter. | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 2/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Cgi-rescue Shopping Basket Professional | 30/1/2007 | 16/6/2026 | CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors. |