Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%—Amazing Flash Commerce Afcommerce Shopping Cart24/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.
ModificadaAlta (7.5)1.6%—Amazing Flash Commerce Afcommerce Shopping Cart24/7/200616/6/2026
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried.
ModificadaMedia (5.8)1.4%—Boxcar Media Shopping Cart13/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php.
ModificadaMedia (4.3)1.3%—Dwzone Shopping Cart15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp.
ModificadaAlta (7.5)1.3%—Pentasoft Corp. Avactis Shopping Cart4/5/200616/6/2026
Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also…
ModificadaBaja (2.6)1.0%—Pentasoft Corp. Avactis Shopping Cart4/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php. NOTE: this issue might be…
ModificadaMedia (5.8)1.9%💥 ExploitTurnkey Solutions Sunshop Shopping Cart1/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php.
ModificadaMedia (5.8)1.8%💥 ExploitNextage Shopping Cart26/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.
ModificadaMedia (5)1.4%—Boxcar Media Shopping Cart7/1/200616/6/2026
Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.
ModificadaMedia (5)1.7%—Modular Merchant Shopping Cart7/1/200616/6/2026
Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
ModificadaAlta (7.5)4.4%💥 ExploitValdersoft Shopping Cart6/1/200616/6/2026
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.
ModificadaMedia (5)1.5%—Turnkey Solutions Sunshop Shopping Cart31/12/200516/6/2026
Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it…
ModificadaAlta (7.5)1.2%—Myezshop Shopping Cart29/12/200516/6/2026
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.2%—Myezshop Shopping Cart29/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.8%💥 ExploitPpcal Shopping Cart17/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.
ModificadaMedia (4.3)1.4%💥 ExploitEdatcat Shopping Cart System16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.
ModificadaMedia (4.3)1.2%—Cartkeeper Ckgold Shopping Cart14/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters.
ModificadaAlta (7.5)1.0%💥 ExploitAsps Shopping Cart5/12/200516/6/2026
Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE:…
ModificadaAlta (7.5)1.3%—Midicart Software Midicart PHP Shopping Cart17/8/200516/6/2026
SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.
ModificadaMedia (4.3)1.7%💥 ExploitNaxtor Shopping Cart5/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModificadaMedia (5)1.2%—Naxtor Shopping Cart5/8/200516/6/2026
shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a "'" (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.
ModificadaMedia (5)1.3%—Craig Dansie Dansie Shopping Cart12/7/200516/6/2026
Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.
ModificadaAlta (7.5)1.2%—India Software Solution Shopping Cart29/5/200516/6/2026
SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaMedia (6.8)3.0%—Midicart Software Midicart PHP Shopping Cart11/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php.
ModificadaAlta (7.5)4.0%💥 ExploitMidicart PHP Shopping CartAI11/5/200516/6/2026
Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php.
Orbitaley — Vulnerabilidades