Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 4/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 3/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 3/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/complex_header_2.php. The manipulation of the argument scripts leads to cross… | |
| Analizada | Media (5.3) | 0.38% | — | Phpgurukul Online Shopping Portal | 3/11/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been classified as problematic. Affected is an unknown function of the file /shopping/admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php. The manipulation of the argument value leads to cross site scripting. It is… | |
| Analizada | Media (5.3) | 0.66% | — | Codezips Online Shopping Portal | 10/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue affects some unknown processing of the file /update-image1.php. The manipulation of the argument productimage1 leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.69% | — | Codezips Online Shopping Portal | 3/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 1.4% | 💥 PoC | Phpgurukul Online Shopping Portal | 29/9/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component Admin Panel. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.73% | — | Codezips Online Shopping Portal | 20/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched… | |
| Aplazada | Alta (8.8) | 0.51% | — | Shopping Cart Ecommerce StoreAI | 20/8/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.8) | 1.0% | 💥 PoC | Puneethreddyhc Online Shopping SystemAI | 5/8/2024 | 17/6/2026 | SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php | |
| Analizada | Media (6.1) | 0.52% | 💥 PoC | Phpgurukul Online Shopping Portal | 18/7/2024 | 17/6/2026 | The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to… | |
| Aplazada | Media (6.3) | 0.29% | — | Buy-addons BagoogleshoppingAI | 19/6/2024 | 17/6/2026 | In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL injection via`GenerateCategories::renderCategories(). | |
| Aplazada | Crítica (9.3) | 0.41% | — | Simple PHP Shopping CartAI | 16/5/2024 | 17/6/2026 | SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file. | |
| Aplazada | Media (6.1) | 0.27% | — | Online Shopping System AdvancedAI | 14/5/2024 | 17/6/2026 | Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. | |
| Aplazada | Media (5.3) | 0.50% | — | Woothemes Shopping Cart Ecommerce StoreAI | 14/5/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details,… | |
| Analizada | Media (6.1) | 0.57% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file login.php. The manipulation of the argument txtAddress leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.57% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file prodInfo.php. The manipulation of the argument prodId leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (5.4) | 0.52% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file prodList.php. The manipulation of the argument prodType leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (5.4) | 0.52% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.66% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This issue affects some unknown processing of the file prodInfo.php. The manipulation of the argument prodId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.5) | 0.60% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file prodList.php. The manipulation of the argument prodType leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.60% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file search.php. The manipulation of the argument txtSearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Alta (8.8) | 0.56% | — | Wpsafe Shopping Cart Ecommerce StoreAI | 12/4/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.4) | 0.35% | — | Lightspeedhq Ecwid Ecommerce Shopping CartAI | 9/4/2024 | 17/6/2026 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Analizada | Media (6.1) | 0.51% | — | Campcodes Online Shopping System | 23/3/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects unknown code of the file /offersmail.php. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… |