Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Midicart Software Midicart PHP Shopping Cart11/5/200516/6/2026
MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message.
ModificadaAlta (7.5)1.2%—Valdersoft Shopping Cart2/5/200516/6/2026
Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the…
ModificadaMedia (4.3)1.0%—Valdersoft Shopping Cart28/3/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php.
ModificadaAlta (7.5)1.2%—Igeneric Free Shopping Cart21/2/200516/6/2026
Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.
ModificadaMedia (5)1.4%—Cassiopeia S-mart Shopping CartItransact Redicart31/12/200416/6/2026
S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name.
ModificadaMedia (5)2.0%💥 ExploitDansie Shopping Cart31/12/200316/6/2026
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.
ModificadaAlta (7.5)2.9%💥 ExploitTurnkey Solutions Sunshop Shopping Cart3/7/200216/6/2026
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.
ModificadaAlta (7.5)3.9%💥 ExploitHassan Consulting Shopping Cart8/9/200116/6/2026
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
ModificadaMedia (5)1.1%—Dansie Shopping Cart31/12/200023/9/2026
Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.
ModificadaAlta (7.5)7.0%💥 ExploitSmartwin Technology Cyberoffice Shopping Cart19/12/200025/9/2026
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
ModificadaMedia (5)7.9%💥 ExploitSmartwin Technology Cyberoffice Shopping Cart19/12/200023/9/2026
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)8.1%💥 ExploitHassan Consulting Shopping Cart19/12/200023/9/2026
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.
ModificadaAlta (7.5)2.4%—Pdgsoft PDG Shopping Cart1/5/200016/6/2026
Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.
ModificadaMedia (5)6.0%💥 ExploitCraig Dansie Dansie Shopping Cart14/4/200016/6/2026
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.
ModificadaMedia (5)2.2%—Craig Dansie Dansie Shopping Cart11/4/200016/6/2026
The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.
ModificadaAlta (10)2.5%—Craig Dansie Dansie Shopping Cart11/4/200016/6/2026
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.
ModificadaMedia (5)1.3%—Pdgsoft PDG Shopping Cart1/4/199916/6/2026
An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information.
Orbitaley — Vulnerabilidades