Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1842 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.3%—Kansok Communications Shopweezle11/4/200616/6/2026
index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter.
ModificadaAlta (7.5)2.3%💥 ExploitKansok Communications Shopweezle11/4/200616/6/2026
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure…
ModificadaMedia (5)1.1%—Ecotwo Shopsystem11/4/200616/6/2026
Unspecified vulnerability in ecotwo Shopsystem 1.0-192 and earlier allows remote attackers to include arbitrary local files via (1) the lang parameter in news.php and (2) other unspecified vectors.
ModificadaMedia (4.3)1.2%—Apt-webshop-system11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality.
ModificadaAlta (7.5)1.1%💥 ExploitApt-webshop-system11/4/200616/6/2026
Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality. NOTE: this vulnerability also allows resultant path…
ModificadaMedia (4.3)1.7%💥 ExploitTalentsoft Web+ Shop11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script.
ModificadaMedia (5)1.2%—Apt-webshop-system11/4/200616/6/2026
Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.
ModificadaAlta (7.5)1.4%—Sourceworkshop Newsletter30/3/200616/6/2026
SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.
ModificadaAlta (7.5)1.4%—Source Workshop Vcounter30/3/200616/6/2026
SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable).
ModificadaMedia (6.5)2.3%💥 ExploitFree Host Shop Website Generator28/2/200616/6/2026
Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.
ModificadaAlta (7.5)72%💥 ExploitMicrosoft Html HelpMicrosoft Html Help Workshop6/2/200616/6/2026
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.
ModificadaMedia (4.3)3.6%💥 ExploitCybershop ASP Ultimate E-commerce Script4/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter.
ModificadaMedia (4.3)4.0%💥 ExploitMedia2 CMS Shop4/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute.
ModificadaMedia (4.6)1.3%—Adobe AcrobatAdobe Acrobat ReaderAdobe Creative SuiteAdobe Illustrator+52/2/200616/6/2026
Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
ModificadaAlta (7.5)1.5%—Gencbeyin WEB Programlama Cybershop25/1/200616/6/2026
Vulnerabilidad de inyección de SQL en CyberShop permite a atacantes remotos ejecutar órdenes SQL de su elección y saltarse la autenticación mediante el parámetro "username" en una acción de inicio de sesión.
ModificadaMedia (5)1.7%—Modular Merchant Shopping Cart7/1/200616/6/2026
Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
ModificadaMedia (5)1.4%—Boxcar Media Shopping Cart7/1/200616/6/2026
Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.
ModificadaAlta (7.5)4.4%💥 ExploitValdersoft Shopping Cart6/1/200616/6/2026
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.
ModificadaMedia (5)1.6%—THE Media Shoppe Berhad Tmspublisher31/12/200516/6/2026
_Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message.
ModificadaAlta (7.5)1.5%—SUM Effect Software Digishop31/12/200516/6/2026
Multiple SQL injection vulnerabilities in digiSHOP 3.1.17 and earlier allow remote attackers to execute arbitrary SQL commands or obtain the full installation path via (1) the c parameter in cart.php and (2) unspecified search module parameters.
ModificadaMedia (5)1.5%—Turnkey Solutions Sunshop Shopping Cart31/12/200516/6/2026
Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it…
ModificadaMedia (4.3)1.3%—THE Media Shoppe Berhad Tmspublisher31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER 3.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (4.3)1.2%—Myezshop Shopping Cart29/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.2%—Myezshop Shopping Cart29/12/200516/6/2026
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.2%—Netdirect Shopengine28/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.