Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Ecomstudio PHP Easy Shopping Cart | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (4.3) | 0.88% | — | Vpasp Vp-asp Shopping Cart | 28/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and… | |
| Modificada | Media (5) | 1.6% | — | Vpasp Vp-asp Shopping Cart | 28/4/2010 | 16/6/2026 | Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the… | |
| Modificada | Alta (7.5) | 1.1% | — | Vpasp Vp-asp Shopping Cart | 28/4/2010 | 16/6/2026 | SQL injection vulnerability in the Getwebsess function in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via the websess parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Resalecode PHP Shopping Cart Selling Website Script | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Resalecode PHP Shopping Cart Selling Website Script | 10/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Pentasoft Corp. Avactis Shopping Cart | 13/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in checkout.php in Avactis Shopping Cart 1.8.0 and 1.8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) step_id and (2) CHECKOUT_CZ_BLOWFISH_KEY parameters. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | E-cart Free Shopping Cart | 27/4/2009 | 16/6/2026 | Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Codetoad ASP Shopping Cart Script | 20/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. | |
| Modificada | Alta (7.8) | 2.5% | 💥 Exploit | Rakhisoftware Shopping Cart | 25/2/2009 | 16/6/2026 | RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Rakhisoftware Shopping Cart | 25/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Rakhisoftware Shopping Cart | 25/2/2009 | 16/6/2026 | SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Interspire Shopping Cart | 3/2/2009 | 16/6/2026 | The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bazaarbuilder Ecommerce Shopping Cart | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Vpasp Vp-asp Shopping Cart | 21/1/2009 | 16/6/2026 | VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the password via a direct request for database/shopping650.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ephpscripts E-shop Shopping Cart | 5/1/2009 | 16/6/2026 | SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Yourfreeworld Shopping Cart Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Razorecommerce Shopping Cart | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Turnkeywebtools Sunshop Shopping Cart | 22/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Pozscripts Greencart PHP Shopping Cart | 11/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cartkeeper Ckgold Shopping Cart | 19/6/2008 | 16/6/2026 | SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Turnkeywebtools Sunshop Shopping Cart | 19/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549. | |
| Modificada | Media (6.5) | 0.89% | — | Turnkey Solutions Sunshop Shopping Cart | 30/4/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | 5TH Avenue Software 5TH Avenue Shopping Cart | 23/4/2008 | 16/6/2026 | SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Interspire Shopping Cart | 29/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |