Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%💥 ExploitShopstorenow E-commerce Shopping Cart9/1/200716/6/2026
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
ModificadaMedia (6.8)1.3%—ZEN Cart WEB Shopping Cart31/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.9%💥 ExploitValdersoft Shopping Cart21/12/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php.
ModificadaMedia (6.5)1.2%—Midicart Software Midicart PHP Shopping Cart11/12/200616/6/2026
Unrestricted file upload vulnerability in admin/add.php in Midicart allows remote authenticated users to upload arbitrary .php files, and possibly other files, to the images/ directory under the web root.
ModificadaMedia (5)1.4%—Midicart Software Midicart PHP Shopping Cart11/12/200616/6/2026
viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart.
ModificadaAlta (7.5)1.4%💥 ExploitMidicart Software Midicart ASP Plus Shopping CartMidicart Software Midicart ASP Shopping Cart1/12/200616/6/2026
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to…
ModificadaAlta (7.5)1.4%—Warhound General Shopping Cart1/12/200616/6/2026
SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
ModificadaAlta (7.5)1.4%—Enthrallweb Eshopping Cart24/11/200616/6/2026
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.
ModificadaAlta (7.5)1.1%—Enthrallweb Eshopping Cart24/11/200616/6/2026
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
ModificadaAlta (7.5)1.3%💥 ExploitHpecs Shopping Cart17/11/200616/6/2026
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
ModificadaAlta (7.5)2.4%💥 ExploitChris MAC Gimescripts Shopping Catalog15/11/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.
ModificadaMedia (5)1.2%—Pdshoppro10/10/200616/6/2026
PDshopPro stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) /pdshoppro.mdb, (2) /data/pdshoppro.mdb, or (3) /shoppro/data/pdshoppro.mdb.
ModificadaMedia (6.8)1.6%—Nextage Shopping Cart25/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action in index.php.
ModificadaAlta (7.5)2.6%💥 ExploitKeyvan1 Eshoppingpro19/9/200616/6/2026
SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.
ModificadaMedia (4.3)1.4%—Amazing Flash Commerce Afcommerce Shopping Cart24/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.
ModificadaAlta (7.5)1.6%—Amazing Flash Commerce Afcommerce Shopping Cart24/7/200616/6/2026
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried.
ModificadaMedia (5.8)1.4%—Boxcar Media Shopping Cart13/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php.
ModificadaMedia (4.3)1.3%—Dwzone Shopping Cart15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp.
ModificadaMedia (4.3)1.7%—Preprojects.com PRE Shopping Mall30/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) cid parameter in products.php.
ModificadaMedia (6.8)2.2%—Cosmicphp Cosmicshoppingcart30/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1)…
ModificadaAlta (7.5)1.8%💥 ExploitCosmicphp Cosmicshoppingcart30/5/200616/6/2026
SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.
ModificadaAlta (7.5)1.3%—Pentasoft Corp. Avactis Shopping Cart4/5/200616/6/2026
Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also…
ModificadaBaja (2.6)1.0%—Pentasoft Corp. Avactis Shopping Cart4/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php. NOTE: this issue might be…
ModificadaMedia (5.8)1.9%💥 ExploitTurnkey Solutions Sunshop Shopping Cart1/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php.
ModificadaMedia (5.8)1.8%💥 ExploitNextage Shopping Cart26/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.
Orbitaley — Vulnerabilidades