Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1842 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Sharky E-shop | 23/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en Sharky e-shop v3.05 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de los parámetros (1) maingroup y (2) secondgroup sobre (a) search_prod_list.asp, y (3) maingroup sobre (b) meny2.asp. NOTA: la procedencia de esta información es desconocida; los… | |
| Modificada | Media (4.3) | 1.1% | — | Sharky E-shop | 23/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Sharky e-shop v3.05, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) maingroup y (2)parámetros secondgroup en (a)search_prod_list.asp y el (3)parámetro maingroup en… | |
| Modificada | Media (4.3) | 1.3% | — | Dpivision Tradingeye Shop | 22/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en details.cfm en Tradingeye Shop R4 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro image. | |
| Modificada | Alta (7.5) | 1.3% | — | TPL Design Tplshop | 22/6/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en category.php en TPL Design tplShop v2.0 y anteriores , permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro first_row. | |
| Modificada | Media (4.3) | 1.2% | — | Cutting Edge Computing Edge Ecommerce Shop | 22/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en productDetail.asp en Edge eCommerce Shop, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro cart_id . | |
| Modificada | Media (4.3) | 1.3% | — | Thinkfactory Ultimate Eshop | 22/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.cgi en Ultimate eShop v1.0 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro subid. | |
| Modificada | Media (4.3) | 1.3% | — | Dwzone Shopping Cart | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp. | |
| Modificada | Alta (7.5) | 1.2% | — | Viart LTD Viart Shop Free | 12/6/2006 | 16/6/2026 | SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id parameter. | |
| Modificada | Baja (2.6) | 2.1% | — | Viart Shop | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not properly handled in block_forum_topics.php,… | |
| Modificada | Media (5) | 1.6% | — | A.shopkart | 5/6/2006 | 16/6/2026 | Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) admin/scart.mdb and possibly (2) admin/scart97.mdb. | |
| Modificada | Alta (7.5) | 5.7% | 💥 Exploit | Ishopcart | 5/6/2006 | 16/6/2026 | Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount… | |
| Modificada | Alta (7.8) | 2.2% | — | Ishopcart | 5/6/2006 | 16/6/2026 | Directory traversal vulnerability in easy-scart.cgi in iShopCart allows remote attackers to read arbitrary files via a .. (dot dot) in the query string. | |
| Modificada | Media (4.3) | 1.7% | — | Preprojects.com PRE Shopping Mall | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) cid parameter in products.php. | |
| Modificada | Media (6.8) | 2.2% | — | Cosmicphp Cosmicshoppingcart | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, as demonstrated by the (1)… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Cosmicphp Cosmicshoppingcart | 30/5/2006 | 16/6/2026 | SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cosmoshop | 19/5/2006 | 16/6/2026 | SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter. | |
| Modificada | Alta (7.8) | 1.7% | — | Cosmoshop | 19/5/2006 | 16/6/2026 | Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | |
| Modificada | Baja (2.6) | 1.0% | — | Pentasoft Corp. Avactis Shopping Cart | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php. NOTE: this issue might be… | |
| Modificada | Alta (7.5) | 1.3% | — | Pentasoft Corp. Avactis Shopping Cart | 4/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also… | |
| Modificada | Media (5.8) | 1.9% | 💥 Exploit | Turnkey Solutions Sunshop Shopping Cart | 1/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Nextage Shopping Cart | 26/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 2.1% | — | Amplecom Ampleshop | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ampleShop 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) RecordID parameter in (a) Customeraddresses_RecordAction.cfm and (b) youraccount.cfm; (2) solus parameter in (c) detail.cfm; and (3) cat parameter in (d) category.cfm. | |
| Modificada | Media (5) | 1.7% | — | Talentsoft Web+ Shop | 20/4/2006 | 16/6/2026 | Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error… | |
| Modificada | Media (6.8) | 1.1% | — | Suche Shopxs | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0 allows remote attackers to inject arbitrary web script or HTML via the Suchstring1 (aka search) parameter. | |
| Modificada | Media (6.8) | 4.6% | 💥 Exploit | Interaktiv.shop | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters. |