Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.51%—E-commerce System Project E-commerce System20/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester E-Commerce System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The…
ModificadaAlta (8.1)0.55%—E-commerce System Project E-commerce System20/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester E-Commerce System 1.0. This issue affects some unknown processing of the file /ecommerce/admin/settings/setDiscount.php. The manipulation of the argument id with the input 201737 AND (SELECT 8973 FROM (SELECT(SLEEP(5)))OoAD) leads to…
ModificadaAlta (8.1)0.61%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System20/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. This vulnerability affects unknown code. The manipulation of the argument email/password with the input test1%40test.com ' AND (SELECT 6077 FROM (SELECT(SLEEP(5)))dltn) AND 'PhRa'='PhRa leads to sql injection.…
ModificadaAlta (8.1)0.61%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System20/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file admin/admin_index.php. The manipulation of the argument username/password with the input admin' AND (SELECT 8062 FROM (SELECT(SLEEP(5)))meUD)-- hLiX leads to sql…
ModificadaAlta (8.1)0.61%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System20/3/202317/6/2026
A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file function/edit_customer.php. The manipulation of the argument firstname/mi/lastname with the input a' RLIKE SLEEP(5) AND 'dAbu'='dAbu leads…
ModificadaCrítica (9.8)0.75%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System19/3/202317/6/2026
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.
ModificadaMedia (5.3)0.91%—Alphaware Simple E-commerce System Project Alphaware Simple E-commerce System24/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access controls. It is possible to initiate the…
ModificadaAlta (8.8)0.91%—Moosikay E-commerce System Project Moosikay E-commerce System24/2/202317/6/2026
A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be…
ModificadaMedia (5.4)0.47%—Welcart E-commerce16/1/202317/6/2026
The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.
ModificadaAlta (8.8)1.1%—Welcart E-commerce2/1/202317/6/2026
The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable…
ModificadaMedia (6.5)0.80%—Welcart E-commerce2/1/202317/6/2026
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server.
ModificadaAlta (7.5)2.9%💥 ExploitWelcart E-commerce2/1/202317/6/2026
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
ModificadaMedia (6.5)0.33%—Welcart E-commerce12/12/202217/6/2026
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
ModificadaMedia (5.4)0.47%—Welcart E-commerce12/12/202217/6/2026
The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
ModificadaCrítica (9.8)5.5%💥 ExploitWelcart E-commerce18/11/202217/6/2026
Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.
ModificadaMedia (5.4)0.59%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System5/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. Affected by this issue is some unknown functionality of the file stockin.php. The manipulation of the argument id with the input '"><script>alert(/xss/)</script> leads to cross site scripting. The…
ModificadaAlta (8.8)0.85%—Alphaware E-commerce System Project Alphaware E-commerce System5/8/202217/6/2026
A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown code of the file admin_feature.php of the component Background Management Page. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The…
ModificadaMedia (5.4)0.56%—E-commerce Website Project E-commerce Website3/5/202217/6/2026
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.
ModificadaMedia (6.5)0.47%—EC Cloud E-commerce System Project EC Cloud E-commerce System4/11/202117/6/2026
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
ModificadaAlta (8.8)0.63%—Simple-e-commerce-shopping-cart Project Simple-e-commerce-shopping-cart13/9/202117/6/2026
The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged…
ModificadaMedia (5.4)0.66%—E-commerce Website Project E-commerce Website23/7/202117/6/2026
Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.
ModificadaCrítica (9.8)1.9%—E-commerce Website Project E-commerce Website23/7/202117/6/2026
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php.
ModificadaCrítica (9.8)1.5%—E-commerce Website Project E-commerce Website22/7/202117/6/2026
SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .
ModificadaMedia (6.1)1.0%—Welcart E-commerce22/6/202117/6/2026
Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
ModificadaMedia (6.1)0.62%—Compassplus Tranzware E-commerce Payment Gateway19/3/202117/6/2026
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability