Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.41% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.4) | 0.27% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary… | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions. | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Alta (7.7) | 0.25% | 💥 PoC | Puneethreddyhc Online Shopping System Advanced | 29/7/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.5) | 0.45% | — | Adonesevangelista Agri-trading Online Shopping System | 8/7/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/suppliercontroller.php. The manipulation of the argument supplier leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.5) | 0.55% | — | Adonesevangelista Agri-trading Online Shopping System | 22/6/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Baja (2) | 0.53% | — | Fabian Online Shopping Store | 22/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (6.1) | 0.31% | — | Vigybag Open Source Online ShopAI | 9/6/2025 | 17/6/2026 | A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to a malicious site via a crafted URL. | |
| Analizada | Media (6.9) | 0.48% | — | Phpgurukul Online Shopping Portal | 31/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument Product leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.51% | — | Campcodes Online Shopping PortalPhpgurukul Online Shopping Portal | 22/5/2025 | 17/6/2026 | A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/updateorder.php. Executing manipulation of the argument remark can lead to sql injection. The attack may be performed from remote. The exploit has been published and… | |
| Analizada | Media (5.5) | 0.55% | — | Campcodes Online Shopping PortalPhpgurukul Online Shopping Portal | 22/5/2025 | 17/6/2026 | A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Media (6.9) | 0.51% | — | Campcodes Online Shopping Portal | 22/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.1) | 0.45% | — | Campcodes Online Shopping Portal | 21/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. It is possible to initiate the attack remotely.… | |
| Analizada | Media (6.9) | 0.51% | — | Campcodes Online Shopping Portal | 21/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/insert-product.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.51% | — | Campcodes Online Shopping Portal | 21/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-products.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.51% | — | Campcodes Online Shopping Portal | 21/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Campcodes Online Shopping Portal | 20/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.49% | — | Campcodes Online Shopping Portal | 19/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /my-cart.php. The manipulation of the argument billingaddress leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 0.51% | — | Campcodes Online Shopping Portal | 19/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file /my-account.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 0.54% | — | Campcodes Online Shopping Portal | 18/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… |