Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
364 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Shopstorenow E-commerce Shopping Cart | 9/1/2007 | 16/6/2026 | SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | |
| Modificada | Media (6.8) | 1.3% | — | ZEN Cart WEB Shopping Cart | 31/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Valdersoft Shopping Cart | 21/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php. | |
| Modificada | Media (5) | 1.4% | — | Midicart Software Midicart PHP Shopping Cart | 11/12/2006 | 16/6/2026 | viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart. | |
| Modificada | Media (6.5) | 1.2% | — | Midicart Software Midicart PHP Shopping Cart | 11/12/2006 | 16/6/2026 | Unrestricted file upload vulnerability in admin/add.php in Midicart allows remote authenticated users to upload arbitrary .php files, and possibly other files, to the images/ directory under the web root. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Midicart Software Midicart ASP Plus Shopping CartMidicart Software Midicart ASP Shopping Cart | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to… | |
| Modificada | Alta (7.5) | 1.4% | — | Warhound General Shopping Cart | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Enthrallweb Eshopping Cart | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier. | |
| Modificada | Alta (7.5) | 1.1% | — | Enthrallweb Eshopping Cart | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Hpecs Shopping Cart | 17/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Chris MAC Gimescripts Shopping Catalog | 15/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Nextage Shopping Cart | 25/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action in index.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Keyvan1 Eshoppingpro | 19/9/2006 | 16/6/2026 | SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Amazing Flash Commerce Afcommerce Shopping Cart | 24/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box. | |
| Modificada | Alta (7.5) | 1.6% | — | Amazing Flash Commerce Afcommerce Shopping Cart | 24/7/2006 | 16/6/2026 | SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried. | |
| Modificada | Media (5.8) | 1.4% | — | Boxcar Media Shopping Cart | 13/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php. | |
| Modificada | Media (4.3) | 1.3% | — | Dwzone Shopping Cart | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp. | |
| Modificada | Media (4.3) | 1.7% | — | Preprojects.com PRE Shopping Mall | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) cid parameter in products.php. | |
| Modificada | Media (6.8) | 2.2% | — | Cosmicphp Cosmicshoppingcart | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1)… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Cosmicphp Cosmicshoppingcart | 30/5/2006 | 16/6/2026 | SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter. | |
| Modificada | Baja (2.6) | 1.0% | — | Pentasoft Corp. Avactis Shopping Cart | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php. NOTE: this issue might be… | |
| Modificada | Alta (7.5) | 1.3% | — | Pentasoft Corp. Avactis Shopping Cart | 4/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also… | |
| Modificada | Media (5.8) | 1.9% | 💥 Exploit | Turnkey Solutions Sunshop Shopping Cart | 1/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Nextage Shopping Cart | 26/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters. | |
| Modificada | Media (5) | 1.4% | — | Boxcar Media Shopping Cart | 7/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter. |