Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.55% | — | Adonesevangelista Agri-trading Online Shopping System | 22/6/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.86% | 💥 PoC | Adonesevangelista Agri-trading Online Shopping System | 14/11/2024 | 17/6/2026 | A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total… | |
| Analizada | Media (5.3) | 0.51% | — | Projectworlds Free Download Online Shopping System | 11/11/2024 | 17/6/2026 | A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be… | |
| Aplazada | Crítica (9.8) | 1.0% | 💥 PoC | Puneethreddyhc Online Shopping SystemAI | 5/8/2024 | 17/6/2026 | SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php | |
| Aplazada | Media (6.1) | 0.27% | — | Online Shopping System AdvancedAI | 14/5/2024 | 17/6/2026 | Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. | |
| Analizada | Media (6.1) | 0.51% | — | Campcodes Online Shopping System | 23/3/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects unknown code of the file /offersmail.php. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 0.79% | — | Surya2developer Online Shopping System | 29/2/2024 | 17/6/2026 | A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the input nochizplz'+or+1%3d1+limit+1%23… | |
| Modificada | Crítica (9.8) | 0.69% | — | Online Shopping System Advanced Project Online Shopping System Advanced | 20/6/2023 | 17/6/2026 | A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched… | |
| Modificada | Media (5.4) | 0.59% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 18/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.2% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 29/11/2022 | 17/6/2026 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system | 29/3/2022 | 17/6/2026 | An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products. | |
| Modificada | Alta (7.5) | 1.2% | — | Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system | 29/3/2022 | 17/6/2026 | An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php. | |
| Modificada | Media (4.3) | 0.45% | — | Projectworlds Online Shopping System | 22/12/2021 | 17/6/2026 | In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Online Shopping System | 22/12/2021 | 17/6/2026 | Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php. | |
| Modificada | Crítica (9.8) | 52% | 💥 Exploit | Online-shopping-system-advanced Project Online-shopping-system-advanced | 1/10/2021 | 17/6/2026 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Online-shopping-system-advanced Project Online-shopping-system-advanced | 1/10/2021 | 17/6/2026 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Microburst Ustorekeeper Online Shopping System | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. |