Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.7%💥 ExploitShopex Ecshop28/6/202217/6/2026
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
ModificadaCrítica (9.8)1.6%—Shopex Ecshop2/12/202117/6/2026
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
ModificadaMedia (6.1)0.88%—Shopex Ecshop28/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.
ModificadaCrítica (9.8)1.4%—Shopex Ecshop16/6/202117/6/2026
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
ModificadaCrítica (9.8)1.4%—Shopex Ecshop16/6/202117/6/2026
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
ModificadaCrítica (9.8)1.4%—Shopex Ecshop16/6/202117/6/2026
SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .
ModificadaMedia (5.9)1.5%—Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java20/5/202117/6/2026
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic…
ModificadaAlta (8.8)15%—Microsoft Azure Internet OF Things EdgeMicrosoft Csharp Software Development KIT10/10/201817/6/2026
A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge.
ModificadaMedia (5.6)1.2%—Microsoft C Software Development KITMicrosoft Csharp Software Development KITMicrosoft Java Software Development KIT9/5/201817/6/2026
A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.
ModificadaMedia (5.4)0.27%—Ocshield Datagard VPN + AV9/9/201417/6/2026
The DataGard VPN + AV (aka ocshield.com) application @7F050013 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)0.97%💥 ExploitShopex Ecshop25/5/201016/6/2026
SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.5)3.6%💥 ExploitManiacomputer Mcshoutbox16/10/200916/6/2026
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/.
ModificadaMedia (6.8)2.0%💥 ExploitManiacomputer Mcshoutbox16/10/200916/6/2026
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaMedia (4.3)1.7%💥 ExploitManiacomputer Mcshoutbox16/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
ModificadaAlta (7.5)1.1%💥 ExploitEcshop12/5/200916/6/2026
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action.
ModificadaAlta (7.5)1.2%💥 ExploitComicshout6/3/200916/6/2026
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.
ModificadaAlta (7.5)0.96%💥 ExploitAspindir Pcshey Portal6/8/200816/6/2026
SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitEcshop Epshop31/7/200816/6/2026
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.
ModificadaAlta (7.5)1.2%💥 ExploitComicshout27/5/200816/6/2026
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter.
ModificadaAlta (7.5)2.4%💥 ExploitDicshunary4/12/200616/6/2026
PHP remote file inclusion vulnerability in check_status.php in dicshunary 0.1 alpha allows remote attackers to execute arbitrary PHP code via a URL in the dicshunary_root_path parameter.
ModificadaMedia (6.8)2.2%—Cosmicphp Cosmicshoppingcart30/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1)…
ModificadaAlta (7.5)1.8%💥 ExploitCosmicphp Cosmicshoppingcart30/5/200616/6/2026
SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.
ModificadaMedia (5)2.0%💥 ExploitDcscripts Dcshop12/8/200216/6/2026
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
ModificadaMedia (5)3.9%💥 ExploitDcscripts Dcshop6/12/200116/6/2026
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.
ModificadaMedia (4.6)0.40%—GNU BashTcsh13/9/199616/6/2026
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
Orbitaley — Vulnerabilidades