Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
364 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.86% | 💥 PoC | Adonesevangelista Agri-trading Online Shopping System | 14/11/2024 | 17/6/2026 | A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total… | |
| Modificada | Alta (8.8) | 0.52% | 💥 PoC | Nikoarroyocuraza Online Furniture Shopping Project | 13/11/2024 | 17/6/2026 | A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Analizada | Media (5.3) | 0.51% | — | Projectworlds Free Download Online Shopping System | 11/11/2024 | 17/6/2026 | A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be… | |
| Analizada | Media (5.3) | 0.39% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.43% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Shopping Portal 2.0. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/js_data.php. The manipulation of the argument scripts leads to cross site… | |
| Analizada | Media (5.3) | 0.40% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. The manipulation of the argument scripts leads to cross site scripting. The… | |
| Analizada | Media (5.3) | 0.40% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to launch… | |
| Analizada | Media (5.3) | 0.40% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dymanic_table.php. The manipulation of the argument scripts leads to cross site scripting. The… | |
| Analizada | Media (5.3) | 0.39% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts leads to cross site scripting. The… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_th.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 3/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 3/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/complex_header_2.php. The manipulation of the argument scripts leads to cross… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 3/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been classified as problematic. Affected is an unknown function of the file /shopping/admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php. The manipulation of the argument value leads to cross site scripting. It is… | |
| Analizada | Media (5.3) | 0.66% | — | Codezips Online Shopping Portal | 10/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue affects some unknown processing of the file /update-image1.php. The manipulation of the argument productimage1 leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.69% | — | Codezips Online Shopping Portal | 3/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 1.4% | 💥 PoC | Phpgurukul Online Shopping Portal | 29/9/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component Admin Panel. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.73% | — | Codezips Online Shopping Portal | 20/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched… | |
| Aplazada | Alta (8.8) | 0.51% | — | Shopping Cart Ecommerce StoreAI | 20/8/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.8) | 1.0% | 💥 PoC | Puneethreddyhc Online Shopping SystemAI | 5/8/2024 | 17/6/2026 | SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php | |
| Analizada | Media (6.1) | 0.52% | 💥 PoC | Phpgurukul Online Shopping Portal | 18/7/2024 | 17/6/2026 | The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to… | |
| Aplazada | Media (6.3) | 0.29% | — | Buy-addons BagoogleshoppingAI | 19/6/2024 | 17/6/2026 | In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL injection via`GenerateCategories::renderCategories(). | |
| Aplazada | Crítica (9.3) | 0.41% | — | Simple PHP Shopping CartAI | 16/5/2024 | 17/6/2026 | SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file. | |
| Aplazada | Media (6.1) | 0.27% | — | Online Shopping System AdvancedAI | 14/5/2024 | 17/6/2026 | Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. | |
| Aplazada | Media (5.3) | 0.50% | — | Woothemes Shopping Cart Ecommerce StoreAI | 14/5/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details,… |