Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.41% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 28/9/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. | |
| Aplazada | Alta (8.2) | 0.25% | — | Indieka900 Online-shopping-system-phpAI | 27/10/2025 | 17/6/2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php. | |
| Modificada | Media (5.5) | 0.42% | — | Projectworlds Online Shopping System | 27/10/2025 | 17/6/2026 | A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_submit.php. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.26% | — | Jimit105 Project-online-shopping-websiteAI | 12/10/2025 | 17/6/2026 | A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the… | |
| Aplazada | Crítica (9.8) | 0.33% | 💥 PoC | Puneethreddy Online Shopping System AdvancedAI | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization. | |
| Analizada | Media (6.5) | 0.26% | — | Phpgurukul Online Shopping Portal Project | 2/10/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter. | |
| Analizada | Media (5.5) | 0.48% | — | Projectworlds Online Shopping System | 27/9/2025 | 17/6/2026 | A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Media (6.1) | 0.23% | — | Phpgurukul Online Shopping Portal | 12/9/2025 | 17/6/2026 | PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart. | |
| Aplazada | Media (4.9) | 0.71% | 💥 Exploit | Elex Woocommerce Google ShoppingAI | 6/9/2025 | 17/6/2026 | The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (5.3) | 0.27% | — | Yahoo ShoppingAI | 5/9/2025 | 17/6/2026 | Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack. | |
| Analizada | Media (5.4) | 0.21% | 💥 PoC | Phpgurukul Online Shopping Portal | 4/9/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php. | |
| Modificada | Crítica (9.1) | 0.47% | — | Phpgurukul Online Shopping Portal | 3/9/2025 | 17/6/2026 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. | |
| Analizada | Media (5.5) | 0.56% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.4) | 0.27% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary… | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions. | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.40% | — | Phpgurukul Online Shopping Portal Project | 15/8/2025 | 17/6/2026 | A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Alta (7.7) | 0.25% | 💥 PoC | Puneethreddyhc Online Shopping System Advanced | 29/7/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.5) | 0.45% | — | Fabian Simple Shopping Cart | 14/7/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.45% | — | Fabian Simple Shopping Cart | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.45% | — | Fabian Simple Shopping Cart | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price leads to sql injection. The attack may be initiated remotely. The exploit has been… |