Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%💥 ExploitTurnkeyforms Text Link Sales12/12/200816/6/2026
Vulnerabilidad de inyección SQL en admin.php en TurnkeyForms Text Link Sales permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro "id".
ModificadaAlta (7.5)0.96%💥 ExploitJoomla COM SalesrepMambo COM Salesrep21/2/200816/6/2026
Vulnerabilidad de Inyección SQL del componente com_salesrep de Joomla! and Mambo, permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro rid en una acción showrep en el index.php
ModificadaMedia (5)1.4%—EZ Photo Sales8/8/200716/6/2026
EZPhotoSales 1.9.3 y anteriores tiene una cuenta "admin" por defecto para las galerías, lo cual permite a atacantes remotos acceder a galerías de su elección especificando este nombre de usuario.
ModificadaMedia (5)1.5%—EZ Photo Sales8/8/200716/6/2026
EZPhotoSales 1.9.3 y versiones anteriores permite a atacantes remotos descargar ficheros de imagen mediante (1) una petición directa de un URL bajo OnlineViewing/galleries/ ó (2) navegación del interfaz de usuario de galería con JavaScript deshabilitado.
ModificadaAlta (8.5)1.8%—EZ Photo Sales8/8/200716/6/2026
Vulnerabilidad de envío de archivo no restringido en EZPhotoSales 1.9.3 y anteriores permite a administradores autenticados remotamente enviar y ejecutar código PHP de su elección bajo OnlineViewing/galleries/.
ModificadaAlta (7.5)2.1%—EZ Photo Sales8/8/200716/6/2026
EZPhotoSales 1.9.3 y versiones anteriores almacena información confidencial bajo el raíz del web con control de acceso insuficiente, lo cual permite a atacantes remotos descargar (1) un fichero conteniendo contraseñas en texto en claro mediante una petición directa de OnlineViewing/data/galleries.txt, ó (2) un fichero…
ModificadaAlta (7.5)1.3%—Salescart Shopping Cart4/6/200716/6/2026
** EN DISPUTA ** Múltiples vulnerabilidades de inyección SQL en cgi-bin/reorder2.asp en SalesCart Shopping Cart permite a atacantes remotos ejecutar comandos SQL arbitrarios mediante un campo contraseña y otros vectores no especificados. NOTA: El vendedor ha impugnado esta vulnerabilidad argumentando que "Podemos…
ModificadaMedia (6.4)1.2%—Sugarcrm Sugar Sales10/1/200516/6/2026
The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
ModificadaAlta (10)4.2%💥 ExploitSugarcrm Sugar Sales10/1/200516/6/2026
Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other…
ModificadaBaja (2.1)0.46%—Spidersales23/11/200416/6/2026
SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.
ModificadaBaja (2.1)0.50%—Spidersales23/11/200416/6/2026
Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.
ModificadaAlta (10)3.3%💥 ExploitSpidersales23/11/200416/6/2026
SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.
ModificadaMedia (5)1.8%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.
ModificadaMedia (5)1.8%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
ModificadaMedia (6.4)2.0%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.
ModificadaMedia (5.1)1.6%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port…
ModificadaMedia (5)3.3%💥 ExploitSaleslogix Corporation Saleslogix18/10/200416/6/2026
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
ModificadaAlta (7.5)1.5%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
ModificadaAlta (7.5)2.2%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.
ModificadaAlta (7.5)2.1%—Best Software SaleslogixSaleslogix Corporation Saleslogix14/10/200416/6/2026
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.
ModificadaMedia (5)7.8%💥 ExploitCoxco Support A-cartCoxco Support MetacartCoxco Support Midicart ASPCoxco Support Midicart ASP Maxi+311/4/200316/6/2026
MidiCart almacena el fichero de base de datos midicart.mdb bajo la raíz de documentos web, lo que permite a atacantes remotos robar información sensible pidiendo la base de datos directamente.
ModificadaMedia (5)5.4%💥 ExploitSaleslogix Corporation Eviewer3/8/200016/6/2026
The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.
ModificadaAlta (7.5)2.1%—Salescart1/2/200016/6/2026
The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
ModificadaAlta (7.2)0.35%—Acushop Salesbuilder30/7/199916/6/2026
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
Orbitaley — Vulnerabilidades