Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.55%—Adonesevangelista Agri-trading Online Shopping System22/6/202517/6/2026
A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.86%💥 PoCAdonesevangelista Agri-trading Online Shopping System14/11/202417/6/2026
A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total…
AnalizadaMedia (5.3)0.51%—Projectworlds Free Download Online Shopping System11/11/202417/6/2026
A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be…
AplazadaCrítica (9.8)1.0%💥 PoCPuneethreddyhc Online Shopping SystemAI5/8/202417/6/2026
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php
AplazadaMedia (6.1)0.27%—Online Shopping System AdvancedAI14/5/202417/6/2026
Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.
AnalizadaMedia (6.1)0.51%—Campcodes Online Shopping System23/3/202417/6/2026
A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects unknown code of the file /offersmail.php. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaCrítica (9.8)0.79%—Surya2developer Online Shopping System29/2/202417/6/2026
A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the input nochizplz'+or+1%3d1+limit+1%23…
ModificadaCrítica (9.8)0.69%—Online Shopping System Advanced Project Online Shopping System Advanced20/6/202317/6/2026
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched…
ModificadaMedia (5.4)0.59%—Online-shopping-system-advanced Project Online-shopping-system-advanced18/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaCrítica (9.8)1.2%—Online-shopping-system-advanced Project Online-shopping-system-advanced29/11/202217/6/2026
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
ModificadaCrítica (9.8)1.7%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
ModificadaAlta (7.5)1.2%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
ModificadaMedia (4.3)0.45%—Projectworlds Online Shopping System22/12/202117/6/2026
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
ModificadaCrítica (9.8)1.1%—Projectworlds Online Shopping System22/12/202117/6/2026
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
ModificadaCrítica (9.8)52%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
ModificadaAlta (7.5)10%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
ModificadaMedia (5)6.5%💥 ExploitMicroburst Ustorekeeper Online Shopping System18/6/200116/6/2026
Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Orbitaley — Vulnerabilidades