Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Merchandise Online Store Project Merchandise Online Store | 13/5/2022 | 17/6/2026 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. | |
| Modificada | Crítica (9.8) | 1.1% | — | Merchandise Online Store Project Merchandise Online Store | 13/5/2022 | 17/6/2026 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. | |
| Modificada | Crítica (9.8) | 1.1% | — | Merchandise Online Store Project Merchandise Online Store | 13/5/2022 | 17/6/2026 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. | |
| Modificada | Media (6.5) | 0.94% | — | Merchandise Online Store Project Merchandise Online Store | 13/5/2022 | 17/6/2026 | Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img. | |
| Modificada | Crítica (9.8) | 1.2% | — | Cosmetics AND Beauty Product Online Store Project Cosmetics AND Beauty Product Online Store | 2/3/2022 | 17/6/2026 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | |
| Modificada | Crítica (9.6) | 1.0% | — | Cosmetics AND Beauty Product Online Store Project Cosmetics AND Beauty Product Online Store | 2/3/2022 | 17/6/2026 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app. | |
| Modificada | Media (5.3) | 1.9% | — | Online Store System Project Online Store System | 1/10/2019 | 17/6/2026 | Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion. | |
| Modificada | Alta (7.5) | 1.4% | — | Online Store System Project Online Store System | 1/10/2019 | 17/6/2026 | Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal. | |
| Modificada | Media (6.1) | 1.2% | — | Online Store System Project Online Store System | 1/10/2019 | 17/6/2026 | Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected. | |
| Modificada | Media (5.4) | 0.76% | — | Online Store System Project Online Store System | 1/10/2019 | 17/6/2026 | Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable | |
| Modificada | Media (5.4) | 0.77% | — | Online Store System Project Online Store System | 1/10/2019 | 17/6/2026 | Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | E-topbiz Online Store | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | E-topbiz Online Store | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Bearrivernet.net I-pos Internet PAY Online Store | 10/6/2008 | 16/6/2026 | SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter. |