Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.12% | — | Tekrom Technology INC T-soft E-commerceAI | 1/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Forgery. This issue affects T-Soft E-Commerce: through 28112025. | |
| Analizada | Media (5.4) | 0.25% | — | Bhabishya-123 E-commerce | 18/11/2025 | 17/6/2026 | A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or page fragment) and inserts it into the DOM via unsafe sinks (innerHTML/insertAdjacentHTML/document.write)… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 28/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_update.php. This manipulation of the argument supp_name/supp_address causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 27/10/2025 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 27/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/supplier_add.php. The manipulation of the argument supp_name/supp_address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.4) | 0.27% | — | Conversios Enhanced-e-commerce-for-woocommerce-storeAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Conversios Conversios.io enhanced-e-commerce-for-woocommerce-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through <= 7.2.13. | |
| Aplazada | Media (6.1) | 0.27% | 💥 PoC | Bhabishya-123 E-commerceAI | 20/10/2025 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious link… | |
| Aplazada | Crítica (9.8) | 0.58% | 💥 PoC | Bhabishya-123 E-commerceAI | 20/10/2025 | 17/6/2026 | SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authentication and gain full access. | |
| Aplazada | Media (6.1) | 0.26% | 💥 PoC | Bhabishya-123 E-commerceAI | 20/10/2025 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoint. Unsanitized input in the /search parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian E-commerce Website | 11/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of the file /pages/delete_order_details.php. Executing manipulation of the argument order_id can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 11/10/2025 | 30/9/2026 | A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument prod_id leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian E-commerce Website | 9/10/2025 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/user_index_search.php. Performing manipulation of the argument Search results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.48% | — | Fabian E-commerce Website | 9/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/supplier_update.php. This manipulation of the argument supp_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Modificada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 8/10/2025 | 17/6/2026 | A flaw has been found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/supplier_add.php. Executing manipulation of the argument supp_email can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Modificada | Baja (2.1) | 0.40% | — | Fabian E-commerce Website | 8/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/product_add.php. Performing manipulation of the argument prod_name results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the argument register_username results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /cart.php. The manipulation of the argument remove results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian E-commerce Website | 8/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/edit_order_details.php. The manipulation of the argument order_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.5) | 0.34% | — | Neto E-commerce CMSAI | 1/10/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter. | |
| Analizada | Media (5.5) | 0.41% | — | Fabian E-commerce Site | 28/9/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/admin_product_details.php. Such manipulation of the argument prod_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.51% | — | Fabian E-commerce Website | 26/9/2025 | 17/6/2026 | A vulnerability was identified in code-projects E-Commerce Website 1.0. This affects an unknown function of the file /pages/admin_account_update.php. Such manipulation of the argument user_id leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.51% | — | Fabian E-commerce Website | 26/9/2025 | 30/9/2026 | A security flaw has been discovered in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/admin_index_search.php. Performing manipulation of the argument Search results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be… | |
| Analizada | Media (5.5) | 0.59% | — | Fabian E-commerce Website | 22/9/2025 | 17/6/2026 | A vulnerability was detected in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/admin_account_delete.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Media (4.6) | 0.24% | — | Akilli Ticaret Software Technologies Smart Trade E-commerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. Smart Trade E-Commerce allows Reflected XSS. This issue affects Smart Trade E-Commerce: before 4.5.0.0.1. |