Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Shopex Ecshop | 28/6/2022 | 17/6/2026 | ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.6% | — | Shopex Ecshop | 2/12/2021 | 17/6/2026 | ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php. | |
| Modificada | Media (6.1) | 0.88% | — | Shopex Ecshop | 28/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability. | |
| Modificada | Crítica (9.8) | 1.4% | — | Shopex Ecshop | 16/6/2021 | 17/6/2026 | SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Shopex Ecshop | 16/6/2021 | 17/6/2026 | SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Shopex Ecshop | 16/6/2021 | 17/6/2026 | SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. . | |
| Modificada | Media (5.9) | 1.5% | — | Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java | 20/5/2021 | 17/6/2026 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic… | |
| Modificada | Alta (8.8) | 15% | — | Microsoft Azure Internet OF Things EdgeMicrosoft Csharp Software Development KIT | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge. | |
| Modificada | Media (5.6) | 1.2% | — | Microsoft C Software Development KITMicrosoft Csharp Software Development KITMicrosoft Java Software Development KIT | 9/5/2018 | 17/6/2026 | A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. | |
| Modificada | Media (5.4) | 0.27% | — | Ocshield Datagard VPN + AV | 9/9/2014 | 17/6/2026 | The DataGard VPN + AV (aka ocshield.com) application @7F050013 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Shopex Ecshop | 25/5/2010 | 16/6/2026 | SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ecshop | 12/5/2009 | 16/6/2026 | SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Comicshout | 6/3/2009 | 16/6/2026 | SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Aspindir Pcshey Portal | 6/8/2008 | 16/6/2026 | SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ecshop Epshop | 31/7/2008 | 16/6/2026 | SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Comicshout | 27/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Dicshunary | 4/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in check_status.php in dicshunary 0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in the dicshunary_root_path parameter. | |
| Modificada | Media (6.8) | 2.2% | — | Cosmicphp Cosmicshoppingcart | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1)… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Cosmicphp Cosmicshoppingcart | 30/5/2006 | 16/6/2026 | SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter. | |
| Modificada | Media (5) | 2.0% | 💥 Exploit | Dcscripts Dcshop | 12/8/2002 | 16/6/2026 | dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | Dcscripts Dcshop | 6/12/2001 | 16/6/2026 | The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt. | |
| Modificada | Media (4.6) | 0.40% | — | GNU BashTcsh | 13/9/1996 | 16/6/2026 | (1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable. |