Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Valdersoft Shopping Cart | 28/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Igeneric Free Shopping Cart | 21/2/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters. | |
| Modificada | Media (5) | 1.4% | — | Cassiopeia S-mart Shopping CartItransact Redicart | 31/12/2004 | 16/6/2026 | S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name. | |
| Modificada | Media (5) | 2.0% | 💥 Exploit | Dansie Shopping Cart | 31/12/2003 | 16/6/2026 | cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message. | |
| Modificada | Media (4.3) | 1.2% | — | Cows CGI Online Worldweb Shopping | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CGI Online Worldweb Shopping 1.1 (a.k.a. COWS) allows remote attackers to execute arbitrary script as other users by injecting script into (1) diagnose.cgi or (2) compatible.cgi. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Turnkey Solutions Sunshop Shopping Cart | 3/7/2002 | 16/6/2026 | Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Hassan Consulting Shopping Cart | 8/9/2001 | 16/6/2026 | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Kabotie Software Technologies Shopplus Cart | 5/9/2001 | 16/6/2026 | shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Microburst Ustorekeeper Online Shopping System | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Alex Heiphetz Group Ezshopper | 9/1/2001 | 16/6/2026 | loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter. | |
| Modificada | Media (5) | 1.1% | — | Dansie Shopping Cart | 31/12/2000 | 23/9/2026 | Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Hassan Consulting Shopping Cart | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Bytes Interactive WEB Shopper | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Smartwin Technology Cyberoffice Shopping Cart | 19/12/2000 | 25/9/2026 | SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Smartwin Technology Cyberoffice Shopping Cart | 19/12/2000 | 23/9/2026 | The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 2.4% | — | Pdgsoft PDG Shopping Cart | 1/5/2000 | 16/6/2026 | Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Craig Dansie Dansie Shopping Cart | 14/4/2000 | 16/6/2026 | The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables. | |
| Modificada | Media (5) | 2.2% | — | Craig Dansie Dansie Shopping Cart | 11/4/2000 | 16/6/2026 | The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable. | |
| Modificada | Alta (10) | 2.5% | — | Craig Dansie Dansie Shopping Cart | 11/4/2000 | 16/6/2026 | The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields. | |
| Modificada | Alta (7.5) | 3.0% | — | Alex Heiphetz Group Ezshopper | 27/2/2000 | 16/6/2026 | EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | |
| Modificada | Alta (7.5) | 8.5% | 💥 Exploit | Alex Heiphetz Group Ezshopper | 27/2/2000 | 16/6/2026 | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | |
| Modificada | Media (5) | 1.3% | — | Pdgsoft PDG Shopping Cart | 1/4/1999 | 16/6/2026 | An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information. |