Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.4% | — | Viart Shopping Cart | 11/10/2007 | 16/6/2026 | Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cartkeeper Ckgold Shopping Cart | 6/9/2007 | 16/6/2026 | SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 30/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549. | |
| Modificada | Alta (10) | 2.2% | — | E-commerce Solutions Auction ScriptE-commerce Solutions Multi-vendor E-shop ScriptE-commerce Solutions Shopping Cart Script | 1/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from… | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected. | |
| Modificada | Alta (7.5) | 1.3% | — | Salescart Shopping Cart | 4/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo… | |
| Modificada | Media (6.8) | 1.7% | — | Vp-asp Shopping Cart | 22/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter. | |
| Modificada | Media (6.4) | 1.0% | — | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation." | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 2/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Shopstorenow E-commerce Shopping Cart | 9/1/2007 | 16/6/2026 | SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | |
| Modificada | Media (6.8) | 1.3% | — | ZEN Cart WEB Shopping Cart | 31/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Valdersoft Shopping Cart | 21/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php. | |
| Modificada | Media (5) | 1.4% | — | Midicart Software Midicart PHP Shopping Cart | 11/12/2006 | 16/6/2026 | viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart. | |
| Modificada | Media (6.5) | 1.2% | — | Midicart Software Midicart PHP Shopping Cart | 11/12/2006 | 16/6/2026 | Unrestricted file upload vulnerability in admin/add.php in Midicart allows remote authenticated users to upload arbitrary .php files, and possibly other files, to the images/ directory under the web root. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Midicart Software Midicart ASP Plus Shopping CartMidicart Software Midicart ASP Shopping Cart | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to… | |
| Modificada | Alta (7.5) | 1.4% | — | Warhound General Shopping Cart | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Enthrallweb Eshopping Cart | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier. | |
| Modificada | Alta (7.5) | 1.1% | — | Enthrallweb Eshopping Cart | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Hpecs Shopping Cart | 17/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp. | |
| Modificada | Media (6.8) | 1.6% | — | Nextage Shopping Cart | 25/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action in index.php. |