Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Merchandise Online Store Project Merchandise Online Store13/5/202217/6/2026
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
ModificadaCrítica (9.8)1.1%—Merchandise Online Store Project Merchandise Online Store13/5/202217/6/2026
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
ModificadaCrítica (9.8)1.1%—Merchandise Online Store Project Merchandise Online Store13/5/202217/6/2026
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
ModificadaMedia (6.5)0.94%—Merchandise Online Store Project Merchandise Online Store13/5/202217/6/2026
Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.
ModificadaCrítica (9.8)1.2%—Cosmetics AND Beauty Product Online Store Project Cosmetics AND Beauty Product Online Store2/3/202217/6/2026
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
ModificadaCrítica (9.6)1.0%—Cosmetics AND Beauty Product Online Store Project Cosmetics AND Beauty Product Online Store2/3/202217/6/2026
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.
ModificadaMedia (5.3)1.9%—Online Store System Project Online Store System1/10/201917/6/2026
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.
ModificadaAlta (7.5)1.4%—Online Store System Project Online Store System1/10/201917/6/2026
Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.
ModificadaMedia (6.1)1.2%—Online Store System Project Online Store System1/10/201917/6/2026
Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected.
ModificadaMedia (5.4)0.76%—Online Store System Project Online Store System1/10/201917/6/2026
Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable
ModificadaMedia (5.4)0.77%—Online Store System Project Online Store System1/10/201917/6/2026
Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.
ModificadaAlta (7.5)1.0%💥 ExploitE-topbiz Online Store31/12/200816/6/2026
SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitE-topbiz Online Store31/12/200816/6/2026
SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaAlta (7.5)0.93%💥 ExploitBearrivernet.net I-pos Internet PAY Online Store10/6/200816/6/2026
SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.
Orbitaley — Vulnerabilidades