Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)2.4%—Viart Shopping Cart11/10/200716/6/2026
Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP…
ModificadaAlta (7.5)1.0%💥 ExploitCartkeeper Ckgold Shopping Cart6/9/200716/6/2026
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart30/8/200716/6/2026
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.
ModificadaAlta (10)2.2%—E-commerce Solutions Auction ScriptE-commerce Solutions Multi-vendor E-shop ScriptE-commerce Solutions Shopping Cart Script1/8/200716/6/2026
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from…
ModificadaAlta (7.5)7.7%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.
ModificadaMedia (4.3)1.9%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
ModificadaMedia (6.8)1.1%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
ModificadaAlta (7.5)1.3%—Salescart Shopping Cart4/6/200716/6/2026
Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo…
ModificadaMedia (6.8)1.7%—Vp-asp Shopping Cart22/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter.
ModificadaMedia (6.4)1.0%—Turnkey WEB Tools Sunshop Shopping Cart9/5/200716/6/2026
Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation."
ModificadaAlta (7.5)1.2%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart9/5/200716/6/2026
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.
ModificadaMedia (4.3)1.6%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart9/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter.
ModificadaAlta (7.5)6.2%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart2/5/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.
ModificadaAlta (7.5)9.4%💥 ExploitTurnkey WEB Tools Sunshop Shopping Cart18/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.
ModificadaAlta (7.5)1.3%💥 ExploitShopstorenow E-commerce Shopping Cart9/1/200716/6/2026
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
ModificadaMedia (6.8)1.3%—ZEN Cart WEB Shopping Cart31/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.9%💥 ExploitValdersoft Shopping Cart21/12/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludePath parameter to (1) admin/include/common.php, (2) include/common.php, or (3) common_include/common.php.
ModificadaMedia (5)1.4%—Midicart Software Midicart PHP Shopping Cart11/12/200616/6/2026
viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart.
ModificadaMedia (6.5)1.2%—Midicart Software Midicart PHP Shopping Cart11/12/200616/6/2026
Unrestricted file upload vulnerability in admin/add.php in Midicart allows remote authenticated users to upload arbitrary .php files, and possibly other files, to the images/ directory under the web root.
ModificadaAlta (7.5)1.4%💥 ExploitMidicart Software Midicart ASP Plus Shopping CartMidicart Software Midicart ASP Shopping Cart1/12/200616/6/2026
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to…
ModificadaAlta (7.5)1.4%—Warhound General Shopping Cart1/12/200616/6/2026
SQL injection vulnerability in item.asp in WarHound General Shopping Cart allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
ModificadaAlta (7.5)1.4%—Enthrallweb Eshopping Cart24/11/200616/6/2026
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.
ModificadaAlta (7.5)1.1%—Enthrallweb Eshopping Cart24/11/200616/6/2026
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
ModificadaAlta (7.5)1.3%💥 ExploitHpecs Shopping Cart17/11/200616/6/2026
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
ModificadaMedia (6.8)1.6%—Nextage Shopping Cart25/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action in index.php.
Orbitaley — Vulnerabilidades