Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.66% | — | Codezips E-commerce Site | 19/12/2024 | 17/6/2026 | A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (6.9) | 0.64% | — | Codezips E-commerce Site | 19/12/2024 | 17/6/2026 | A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file signin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (7.1) | 0.35% | — | Jacob Schwartz WP E-commerce Style EmailAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Schwartz WP e-Commerce Style Email wp-e-commerce-style-email allows Reflected XSS.This issue affects WP e-Commerce Style Email: from n/a through <= 0.6.2. | |
| Analizada | Media (6.9) | 0.89% | — | Codezips E-commerce Site | 25/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument keywords leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (6.5) | 0.34% | — | Special Minds Design AND Software E-commerceAI | 22/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Design and Software e-Commerce allows SQL Injection. This issue affects e-Commerce: before 22.11.2024. | |
| Analizada | Media (6.1) | 0.26% | — | Welcart E-commerce | 18/9/2024 | 17/6/2026 | Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser. | |
| Analizada | Alta (8.8) | 0.48% | — | Welcart E-commerce | 18/9/2024 | 17/6/2026 | SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database. | |
| Analizada | Media (6.9) | 0.74% | — | Donbermoy E-commerce Website | 27/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.58% | — | Angeljudesuarez E-commerce Website | 25/8/2024 | 17/6/2026 | A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.70% | — | Janobe E-commerce System | 23/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.60% | — | Janobe E-commerce System | 22/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.69% | — | Janobe E-commerce System | 22/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the component Admin Login. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The… | |
| Modificada | Media (4.3) | 0.34% | — | Welcart E-commerce | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14. | |
| Analizada | Media (5.3) | 0.69% | — | Codezips E-commerce Site | 17/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.71% | — | Codezips E-commerce Site | 16/5/2024 | 17/6/2026 | A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.2) | 0.61% | — | T-soft E-commerceAI | 14/5/2024 | 17/6/2026 | The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view… | |
| Analizada | Crítica (9.8) | 1.1% | — | Donbermoy Complete E-commerce Site | 5/4/2024 | 17/6/2026 | Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php. | |
| Modificada | Media (6.1) | 0.33% | — | Algoritimbilisim E-commerce Software | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Algoritim E-commerce Software allows Reflected XSS. This issue affects E-commerce Software: before 3.9.2. | |
| Analizada | Alta (8.8) | 0.82% | — | Donbermoy Complete E-commerce Site | 21/3/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.1) | 0.83% | — | Fabian E-commerce Website | 29/2/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknown part of the file user_signup.php. The manipulation of the argument firstname with the input <video/src=x onerror=alert(document.domain)> leads to cross site scripting. It is possible to initiate… | |
| Analizada | Crítica (9.8) | 0.92% | — | Fabian E-commerce Website | 29/2/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql injection. The attack may be launched… | |
| Analizada | Alta (8.8) | 0.78% | — | Fabian E-commerce Website | 29/2/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file product_details.php?prod_id=11. The manipulation of the argument prod_id leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.87% | — | Fabian E-commerce Website | 29/2/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Website 1.0. It has been classified as critical. Affected is an unknown function of the file index_search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.1) | 0.45% | — | Tychesoftwares Order Delivery Date FOR WP E-commerce | 5/2/2024 | 17/6/2026 | The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'available-days-tf' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (4.3) | 0.49% | — | Pimcore E-commerce Framework | 11/1/2024 | 17/6/2026 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10. |