Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1842 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Kansok Communications Shopweezle | 11/4/2006 | 16/6/2026 | index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Kansok Communications Shopweezle | 11/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure… | |
| Modificada | Media (5) | 1.1% | — | Ecotwo Shopsystem | 11/4/2006 | 16/6/2026 | Unspecified vulnerability in ecotwo Shopsystem 1.0-192 and earlier allows remote attackers to include arbitrary local files via (1) the lang parameter in news.php and (2) other unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Apt-webshop-system | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Apt-webshop-system | 11/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality. NOTE: this vulnerability also allows resultant path… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Talentsoft Web+ Shop | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script. | |
| Modificada | Media (5) | 1.2% | — | Apt-webshop-system | 11/4/2006 | 16/6/2026 | Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Sourceworkshop Newsletter | 30/3/2006 | 16/6/2026 | SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Source Workshop Vcounter | 30/3/2006 | 16/6/2026 | SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable). | |
| Modificada | Media (6.5) | 2.3% | 💥 Exploit | Free Host Shop Website Generator | 28/2/2006 | 16/6/2026 | Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft Html HelpMicrosoft Html Help Workshop | 6/2/2006 | 16/6/2026 | Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Cybershop ASP Ultimate E-commerce Script | 4/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Media2 CMS Shop | 4/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute. | |
| Modificada | Media (4.6) | 1.3% | — | Adobe AcrobatAdobe Acrobat ReaderAdobe Creative SuiteAdobe Illustrator+5 | 2/2/2006 | 16/6/2026 | Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs. | |
| Modificada | Alta (7.5) | 1.5% | — | Gencbeyin WEB Programlama Cybershop | 25/1/2006 | 16/6/2026 | Vulnerabilidad de inyección de SQL en CyberShop permite a atacantes remotos ejecutar órdenes SQL de su elección y saltarse la autenticación mediante el parámetro "username" en una acción de inicio de sesión. | |
| Modificada | Media (5) | 1.7% | — | Modular Merchant Shopping Cart | 7/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Media (5) | 1.4% | — | Boxcar Media Shopping Cart | 7/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Valdersoft Shopping Cart | 6/1/2006 | 16/6/2026 | PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter. | |
| Modificada | Media (5) | 1.6% | — | THE Media Shoppe Berhad Tmspublisher | 31/12/2005 | 16/6/2026 | _Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | SUM Effect Software Digishop | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in digiSHOP 3.1.17 and earlier allow remote attackers to execute arbitrary SQL commands or obtain the full installation path via (1) the c parameter in cart.php and (2) unspecified search module parameters. | |
| Modificada | Media (5) | 1.5% | — | Turnkey Solutions Sunshop Shopping Cart | 31/12/2005 | 16/6/2026 | Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it… | |
| Modificada | Media (4.3) | 1.3% | — | THE Media Shoppe Berhad Tmspublisher | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER 3.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Myezshop Shopping Cart | 29/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Myezshop Shopping Cart | 29/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Netdirect Shopengine | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |