Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.29% | — | Cmcm CM Backup Restore Cloud Photo | 9/9/2014 | 17/6/2026 | The CM Backup -Restore,Cloud,Photo (aka com.ijinshan.kbackup) application 1.1.0.135 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.2) | 0.31% | — | Restorepoint | 13/12/2011 | 16/6/2026 | The Tadasoft Restorepoint 3.2 evaluation image uses weak permissions (www write access) for unspecified scripts, which allows local users to gain privileges by modifying a script file. | |
| Modificada | Alta (9.3) | 2.2% | — | Restorepoint | 13/12/2011 | 16/6/2026 | remote_support.cgi in the Tadasoft Restorepoint 3.2 evaluation image allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) pid1 or (2) pid2 parameter in a stop_remote_support action. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Paypalestores Paypal Estores | 26/3/2009 | 16/6/2026 | admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Estoreaff | 5/8/2008 | 16/6/2026 | SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php. | |
| Modificada | Media (4.3) | 0.52% | — | Buildanichestore3 Bans | 3/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search script in Build A Niche Store (BANS) 3.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Algera ABC Estore | 31/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Quickestore | 21/7/2007 | 16/6/2026 | SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the CFTOKEN parameter, a different vector than CVE-2006-2053. | |
| Modificada | Media (6.4) | 1.6% | — | Quickestore | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in QuickEStore 7.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the OrderID parameter in (a) shipping.cfm and (b) checkout.cfm, (2) ItemID parameter in (c) proddetail.cfm, (3) SubCatID parameter in (d) index.cfm, the (4) CategoryID parameter in (e)… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Dick Copits Pdestore | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters. | |
| Modificada | Alta (10) | 2.2% | — | Veritas Bare Metal Restore | 31/12/2003 | 16/6/2026 | Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Brooky Estore | 18/8/2003 | 16/6/2026 | Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php. | |
| Modificada | Alta (7.5) | 1.6% | — | Brooky Estore | 18/8/2003 | 16/6/2026 | SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters. |