Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

133 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.43%—Online Shop Store Project Online Shop Store8/9/202417/6/2026
A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of the argument error leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
AplazadaCrítica (9.8)1.0%💥 PoCPuneethreddyhc Online Shopping SystemAI5/8/202417/6/2026
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php
AnalizadaMedia (6.1)0.52%💥 PoCPhpgurukul Online Shopping Portal18/7/202417/6/2026
The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to…
AplazadaMedia (6.1)0.27%—Online Shopping System AdvancedAI14/5/202417/6/2026
Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.
AnalizadaMedia (6.1)0.51%—Campcodes Online Shopping System23/3/202417/6/2026
A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects unknown code of the file /offersmail.php. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaCrítica (9.8)0.79%—Surya2developer Online Shopping System29/2/202417/6/2026
A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the input nochizplz'+or+1%3d1+limit+1%23…
AnalizadaMedia (5.4)0.63%—Nayem-howlader SUP Online Shopping21/11/202317/6/2026
Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email and Address parameters in the Register New Account component.
ModificadaAlta (8.8)1.4%💥 PoCPhpgurukul Online Shopping Portal18/8/202317/6/2026
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.
ModificadaAlta (8.8)1.1%💥 PoCPhpgurukul Online Shopping Portal1/8/202317/6/2026
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
ModificadaCrítica (9.1)0.68%—Phpgurukul Online Shopping Portal10/7/202317/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely.…
ModificadaCrítica (9.8)0.69%—Online Shopping System Advanced Project Online Shopping System Advanced20/6/202317/6/2026
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched…
ModificadaMedia (5.4)0.59%—Online-shopping-system-advanced Project Online-shopping-system-advanced18/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaCrítica (9.8)1.2%—Online-shopping-system-advanced Project Online-shopping-system-advanced29/11/202217/6/2026
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
ModificadaCrítica (9.8)1.7%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
ModificadaAlta (7.5)1.2%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
ModificadaCrítica (9.8)1.1%—Phpgurukul Online Shopping Portal18/2/202217/6/2026
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
ModificadaCrítica (9.8)0.97%—Projectworlds Online-shopping-webvsite-in-php23/1/202217/6/2026
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
ModificadaMedia (4.3)0.45%—Projectworlds Online Shopping System22/12/202117/6/2026
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
ModificadaCrítica (9.8)1.1%—Projectworlds Online Shopping System22/12/202117/6/2026
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
ModificadaAlta (7.5)1.5%—Phpgurukul Online Shopping Portal27/10/202117/6/2026
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
ModificadaCrítica (9.8)52%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
ModificadaAlta (7.5)10%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
ModificadaAlta (7.5)2.1%—Online Shopping Alphaware Project Online Shopping Alphaware2/6/202117/6/2026
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
ModificadaCrítica (9.8)3.3%—Online Shopping Alphaware Project Online Shopping Alphaware17/8/202017/6/2026
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
ModificadaMedia (5.4)0.55%—Your Online Shop Project Your Online Shop9/6/202017/6/2026
Your Online Shop 1.8.0 allows authenticated users to trigger XSS via a Change Name or Change Surname operation.
Orbitaley — Vulnerabilidades