Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%💥 Exploit5TH Avenue Software 5TH Avenue Shopping Cart23/4/200816/6/2026
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.
ModificadaMedia (4.3)1.0%—Interspire Shopping Cart29/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.96%💥 ExploitShoppingtree Candypress Store13/2/200816/6/2026
SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter.
ModificadaAlta (7.5)2.3%💥 ExploitShoppingtree Candypress Store13/2/200816/6/2026
SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter.
ModificadaMedia (5)3.1%💥 ExploitShoppingtree Candypress Store13/2/200816/6/2026
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.
ModificadaAlta (7.5)0.96%💥 ExploitShoppingtree Candypress Store13/2/200816/6/2026
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp. NOTE: the…
ModificadaAlta (7.5)3.1%💥 ExploitShoppingtree Candypress Store1/2/200816/6/2026
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp.
ModificadaMedia (4.3)3.7%💥 ExploitShoppingtree Candypress Store1/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.
ModificadaAlta (10)2.4%—Viart Shopping Cart11/10/200716/6/2026
Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP…
ModificadaAlta (7.5)1.0%💥 ExploitCartkeeper Ckgold Shopping Cart6/9/200716/6/2026
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
ModificadaMedia (5)1.8%—Cgi-rescue Shopping Basket Professional4/9/200716/6/2026
Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.
ModificadaAlta (7.5)1.0%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart30/8/200716/6/2026
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.
ModificadaAlta (10)2.2%—E-commerce Solutions Auction ScriptE-commerce Solutions Multi-vendor E-shop ScriptE-commerce Solutions Shopping Cart Script1/8/200716/6/2026
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from…
ModificadaAlta (7.5)7.7%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.
ModificadaMedia (6.8)1.1%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
ModificadaMedia (4.3)1.9%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
ModificadaAlta (7.5)1.3%—Salescart Shopping Cart4/6/200716/6/2026
Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo…
ModificadaMedia (6.8)1.7%—Vp-asp Shopping Cart22/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter.
ModificadaAlta (7.5)1.3%💥 ExploitPRE Projects PRE Shopping Mall14/5/200716/6/2026
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
ModificadaMedia (6.4)1.0%—Turnkey WEB Tools Sunshop Shopping Cart9/5/200716/6/2026
Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation."
ModificadaAlta (7.5)1.2%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart9/5/200716/6/2026
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.
ModificadaMedia (4.3)1.6%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart9/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter.
ModificadaAlta (7.5)6.2%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart2/5/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.
ModificadaAlta (7.5)9.4%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart18/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.
ModificadaAlta (7.5)1.4%—Cgi-rescue Shopping Basket Professional30/1/200716/6/2026
CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.