Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. | |
| Modificada | Alta (10) | 5.2% | 💥 Exploit | Ecommerce Corporation Online Store KIT | 23/11/2004 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Online Store Kit 3.0 permite a atacantes remotos inyectar SQL arbitrario y ganar acceso no autorizado mediante (1) el parámetro cat en shop.php, (2) el parámetro id en more.php, y (3) el parámetro cat_manufacturer en shop_by_brand.php, o (4) el parámetro id en listing.php. | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Ecommerce Corporation Online Store KIT | 23/11/2004 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en more.php de Online Store Kit 3.0 permite a atacantes remotos inyectar código HTML arbitrario mediante el parámetro id. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Webcortex Webstores 2000 | 23/11/2004 | 16/6/2026 | Vulnerabilidad de inyección de SQLen browse_items.asp en WebCortex WebStores 2000 6.0 permite a atacantes remotos ganar acceso no autorizado y ejecutar comandos de su elección mediante el parámetro Search_Text. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Webcortex Webstores 2000 | 23/11/2004 | 16/6/2026 | Vulnerabilidad de secuencias de comados en sitios cruzados (XSS) en error.asp de WebCortex WebStores 2000 6.0 permite a atacantes remotos ejecutar scritp de su elección como otros usuarios y robar IDs de sesión mediante el parámetro Message_id. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Extropia Webstore | 27/7/2004 | 16/6/2026 | Web_Store.cgi permite a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en el parámetro page. | |
| Modificada | Alta (7.2) | 0.37% | — | SUN Storedge 3310 Scsi ArraySUN Storedge 3510 FC ArraySUN Enterprise Storage Manager | 21/6/2004 | 16/6/2026 | Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access. | |
| Modificada | Alta (10) | 2.2% | — | Veritas Bare Metal Restore | 31/12/2003 | 16/6/2026 | Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Lagarde Storefront | 18/8/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en login.asp de StoreFront 6.0, y posiblemente versiones anteriores, permite a atacantes remotos obtener información sensible de usuario mediante sentencias SQL en el campo de contraseña. | |
| Modificada | Alta (7.5) | 1.6% | — | Brooky Estore | 18/8/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en login.asp de Brooky eStore 1.0.1 a 1.0.2b permite a atacantes remotos saltarse la autenticación y ejecutar código SQL arbitrario mediante parámetros user o pass largos. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Brooky Estore | 18/8/2003 | 16/6/2026 | Brooky eStore 1.0.1 a 1.0.2b permite a atacantes remotos obtener información sensible de rutas mediante una petición HTTP directa a settings.inc.php. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Arcadia Internet Store | 20/9/2001 | 16/6/2026 | Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Arcadia Internet Store | 20/9/2001 | 16/6/2026 | tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Arcadia Internet Store | 20/9/2001 | 16/6/2026 | tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Microburst Ustorekeeper Online Shopping System | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Cgicentral Webstore 400Cgicentral Webstore 400cs | 12/6/2001 | 16/6/2026 | ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Cgicentral Webstore 400Cgicentral Webstore 400cs | 12/6/2001 | 16/6/2026 | WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot). | |
| Modificada | Media (5) | 2.4% | — | I-soft Quikstore | 9/1/2001 | 16/6/2026 | Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Extropia Webstore | 11/12/2000 | 16/6/2026 | Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | I-soft Quikstore | 20/11/2000 | 16/6/2026 | quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request. | |
| Modificada | Alta (7.5) | 2.1% | — | Make-a-store Orderpage | 1/2/2000 | 16/6/2026 | The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | |
| Modificada | Media (5) | 1.1% | — | Selena SOL Webstore | 20/4/1999 | 16/6/2026 | An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information. | |
| Modificada | Media (5) | 1.5% | — | I-soft Quikstore | 20/4/1999 | 16/6/2026 | quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges. |