Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1842 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Media2 CMS Shop | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Ppcal Shopping Cart | 17/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Ectools OnlineshopAI | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Edatcat Shopping Cart System | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Nightmedia THE City Shop | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cgi. | |
| Modificada | Media (4.3) | 1.2% | — | Cartkeeper Ckgold Shopping Cart | 14/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Landshop Real Estate Commerce System | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Asps Shopping Cart | 5/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE:… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Amazon Shop | 30/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Randshop | 30/11/2005 | 16/6/2026 | SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | AenovoAenovoshopAenovowysi | 14/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages. | |
| Modificada | Media (4.6) | 0.48% | — | AenovoAenovoshopAenovowysi | 14/10/2005 | 16/6/2026 | Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Interakt MX Shop | 21/9/2005 | 16/6/2026 | SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php. | |
| Modificada | Media (5) | 1.2% | — | Cosmoshop | 2/9/2005 | 16/6/2026 | Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Cosmoshop | 2/9/2005 | 16/6/2026 | SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.33% | — | Cosmoshop | 2/9/2005 | 16/6/2026 | cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information. | |
| Modificada | Media (5) | 1.2% | — | Ecw-shop | 19/8/2005 | 16/6/2026 | index.php in ECW-Shop 6.0.2 allows remote attackers to obtain sensitive information via the (1) min or (2) max parameter with a "'" (single quote), which reveals the path in an error message, possibly due to a SQL injection vulnerability. | |
| Modificada | Media (5) | 1.3% | — | Ecw-shop | 19/8/2005 | 16/6/2026 | ECW-Shop 6.0.2 allows remote attackers to reduce the total cost of their shopping cart by specifying a negative quantity for an item, which causes the price of the item to be subtracted from the total cost. | |
| Modificada | Media (4.3) | 1.8% | — | Ecw-shop | 19/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 6.0.2 allows remote attackers to inject arbitrary web script or HTML via the (1) max or (2) ctg parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Midicart Software Midicart PHP Shopping Cart | 17/8/2005 | 16/6/2026 | SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Naxtor Shopping Cart | 5/8/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en lost_passowrd.php en Naxtor Shopping Cart 1.0 permite que atacantes remotos inyecten código HTML o script mediante el parámetro email. | |
| Modificada | Media (5) | 1.2% | — | Naxtor Shopping Cart | 5/8/2005 | 16/6/2026 | shop_display_products.php en Naxtor Shopping Cart 1.0 permite que atacantes remotos obtengan información restringida mediante un cat_id con una única "" (comillas sencillas). | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… | |
| Modificada | Media (5) | 1.3% | — | Craig Dansie Dansie Shopping Cart | 12/7/2005 | 16/6/2026 | Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables. | |
| Modificada | Alta (7.5) | 1.1% | — | Etoshop Dynamic BIZ Website Builder Quickweb | 5/7/2005 | 16/6/2026 | SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters. |