Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.8% | — | Lockon Ec-cube | 29/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated with the management screen. | |
| Modificada | Media (4) | 1.9% | — | Lockon Ec-cube | 29/5/2013 | 16/6/2026 | Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Lockon Ec-cube | 29/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.3) | 2.0% | — | Roundcube Webmail | 24/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Cubecart | 8/2/2013 | 16/6/2026 | The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Roundcube Webmail | 25/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email. | |
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Roundcube Webmail | 25/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email. | |
| Modificada | Baja (2.6) | 2.1% | — | Roundcube Webmail | 25/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject. | |
| Modificada | Baja (2.6) | 1.8% | — | Roundcube Webmail | 4/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment. | |
| Modificada | Media (5.8) | 2.8% | 💥 Exploit | Cubecart | 21/2/2012 | 16/6/2026 | Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php. | |
| Modificada | Media (5) | 2.3% | — | Roundcube Webmail | 3/11/2011 | 16/6/2026 | include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379. | |
| Modificada | Alta (7.5) | 2.3% | — | Lockon Ec-cube | 21/10/2011 | 16/6/2026 | SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Cubecart | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter. | |
| Modificada | Media (5) | 1.3% | — | Cubecart | 23/9/2011 | 16/6/2026 | CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/shipping/USPS/calc.php and certain other files. | |
| Modificada | Media (4.3) | 2.5% | — | Roundcube Webmail | 21/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI. | |
| Modificada | Media (5.8) | 0.61% | — | Lockon Ec-cube | 13/5/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5.5) | 1.8% | — | Roundcube Webmail | 8/4/2011 | 16/6/2026 | steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive… | |
| Modificada | Baja (3.5) | 1.5% | — | Roundcube Webmail | 8/4/2011 | 16/6/2026 | The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related… | |
| Modificada | Media (4.3) | 1.9% | — | Lockon Ec-cube | 3/2/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) data/Smarty/templates/default/list.tpl and (2) data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cubecart | 10/6/2010 | 16/6/2026 | SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php. | |
| Modificada | Media (5) | 2.0% | — | Roundcube Webmail | 29/1/2010 | 16/6/2026 | Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. | |
| Modificada | Media (5) | 1.5% | — | Ec-cube Ver2 | 8/12/2009 | 16/6/2026 | The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18428, allows remote attackers to obtain sensitive information (customer data) via unknown vectors related to sessions. | |
| Modificada | Media (6.8) | 1.3% | — | Roundcube Webmail | 25/11/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076. | |
| Modificada | Media (6.8) | 1.3% | — | Roundcube Webmail | 25/11/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Cubecart | 24/11/2009 | 16/6/2026 | SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter. |