Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.98% | — | Cubecart | 17/11/2023 | 17/6/2026 | CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command. | |
| Modificada | Media (4.9) | 1.2% | — | Cubecart | 17/11/2023 | 17/6/2026 | Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system. | |
| Modificada | Media (6.5) | 1.3% | — | Cubecart | 17/11/2023 | 17/6/2026 | Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system. | |
| Modificada | Alta (8.1) | 0.35% | — | Cubecart | 17/11/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system. | |
| Modificada | Media (5.4) | 0.70% | — | Cubecart | 27/5/2021 | 17/6/2026 | Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cubecart | 15/1/2019 | 17/6/2026 | CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. | |
| Modificada | Media (5.4) | 0.64% | — | Cubecart | 13/1/2019 | 17/6/2026 | CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string. | |
| Modificada | Media (4.9) | 2.1% | — | Cubecart | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.5) | 2.5% | — | Cubecart | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.5) | 2.5% | — | Cubecart | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.8) | 2.2% | — | Cubecart | 28/9/2015 | 17/6/2026 | classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the… | |
| Modificada | Media (6.8) | 5.8% | 💥 Exploit | Cubecart | 22/4/2014 | 17/6/2026 | Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Cubecart | 8/2/2013 | 16/6/2026 | The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object. | |
| Modificada | Media (5.8) | 2.8% | 💥 Exploit | Cubecart | 21/2/2012 | 16/6/2026 | Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Cubecart | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter. | |
| Modificada | Media (5) | 1.3% | — | Cubecart | 23/9/2011 | 16/6/2026 | CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/shipping/USPS/calc.php and certain other files. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cubecart | 10/6/2010 | 16/6/2026 | SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Cubecart | 24/11/2009 | 16/6/2026 | SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Cubecart | 6/11/2009 | 16/6/2026 | classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3)… | |
| Modificada | Media (4.3) | 1.0% | — | Cubecart | 31/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in CubeCart 4.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the _a parameter in a searchStr action and the (2) Submit parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Devellion Cubecart | 24/5/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an include directory, related to missing sanitization of the $option variable and possibly cookie modification. | |
| Modificada | Media (5) | 2.2% | — | Devellion Cubecart | 9/5/2007 | 16/6/2026 | Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cookie name beginning with "ccSID" to (1) cart.php or (2) index.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Devellion Cubecart | 3/10/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter in view_doc.php, and (4) the order_id parameter in… | |
| Modificada | Media (5) | 1.5% | — | Devellion Cubecart | 3/10/2006 | 16/6/2026 | Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. NOTE: the information.php, language.php, list_docs.php, popular_prod.php, sale.php, check_sum.php, and cat_navi.php vectors… | |
| Modificada | Media (6.8) | 6.1% | 💥 Exploit | Devellion Cubecart | 3/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4) la_search_home parameters and (5) certain language parameters in… |