Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.98%—Cubecart17/11/202317/6/2026
CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.
ModificadaMedia (4.9)1.2%—Cubecart17/11/202317/6/2026
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
ModificadaMedia (6.5)1.3%—Cubecart17/11/202317/6/2026
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.
ModificadaAlta (8.1)0.35%—Cubecart17/11/202317/6/2026
Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
ModificadaMedia (5.4)0.70%—Cubecart27/5/202117/6/2026
Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's…
ModificadaCrítica (9.8)1.2%—Cubecart15/1/201917/6/2026
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
ModificadaMedia (5.4)0.64%—Cubecart13/1/201917/6/2026
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
ModificadaMedia (4.9)2.1%—Cubecart28/4/201717/6/2026
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
ModificadaMedia (6.5)2.5%—Cubecart28/4/201717/6/2026
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.5)2.5%—Cubecart28/4/201717/6/2026
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.8)2.2%—Cubecart28/9/201517/6/2026
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the…
ModificadaMedia (6.8)5.8%💥 ExploitCubecart22/4/201417/6/2026
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
ModificadaCrítica (9.8)7.1%💥 ExploitCubecart8/2/201316/6/2026
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
ModificadaMedia (5.8)2.8%💥 ExploitCubecart21/2/201216/6/2026
Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.
ModificadaAlta (7.5)1.1%—Cubecart8/10/201116/6/2026
SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
ModificadaMedia (5)1.3%—Cubecart23/9/201116/6/2026
CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/shipping/USPS/calc.php and certain other files.
ModificadaAlta (7.5)1.3%💥 ExploitCubecart10/6/201016/6/2026
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.
ModificadaAlta (7.5)2.2%💥 ExploitCubecart24/11/200916/6/2026
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
ModificadaAlta (7.5)8.7%💥 ExploitCubecart6/11/200916/6/2026
classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3)…
ModificadaMedia (4.3)1.0%—Cubecart31/3/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in CubeCart 4.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the _a parameter in a searchStr action and the (2) Submit parameter.
ModificadaAlta (7.5)1.1%—Devellion Cubecart24/5/200716/6/2026
Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an include directory, related to missing sanitization of the $option variable and possibly cookie modification.
ModificadaMedia (5)2.2%—Devellion Cubecart9/5/200716/6/2026
Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cookie name beginning with "ccSID" to (1) cart.php or (2) index.php.
ModificadaAlta (7.5)1.1%💥 ExploitDevellion Cubecart3/10/200616/6/2026
Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter in view_doc.php, and (4) the order_id parameter in…
ModificadaMedia (5)1.5%—Devellion Cubecart3/10/200616/6/2026
Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. NOTE: the information.php, language.php, list_docs.php, popular_prod.php, sale.php, check_sum.php, and cat_navi.php vectors…
ModificadaMedia (6.8)6.1%💥 ExploitDevellion Cubecart3/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4) la_search_home parameters and (5) certain language parameters in…
Orbitaley — Vulnerabilidades