Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1842 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.7% | — | Adobe Creative SuiteAdobe PhotoshopAdobe Premiere | 13/6/2005 | 16/6/2026 | Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges. | |
| Modificada | Alta (7.5) | 1.2% | — | India Software Solution Shopping Cart | 29/5/2005 | 16/6/2026 | SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Codethat Shoppingcart | 16/5/2005 | 16/6/2026 | SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.8% | — | Codethat Shoppingcart | 16/5/2005 | 16/6/2026 | CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Media (4.3) | 0.94% | — | Metalinks Metacart E-shop | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter. | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Codethat Shoppingcart | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Midicart Software Midicart PHP Shopping Cart | 11/5/2005 | 16/6/2026 | MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Midicart PHP Shopping CartAI | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php. | |
| Modificada | Media (6.8) | 3.0% | — | Midicart Software Midicart PHP Shopping Cart | 11/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php. | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Codetosell Viart Shop Enterprise | 3/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php,… | |
| Modificada | Alta (7.5) | 1.3% | — | Metalinks Metacart E-shop | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Interakt MX Shop | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id_ctg parameter. | |
| Modificada | Media (5) | 1.9% | — | Arpanet Perlshop | 2/5/2005 | 16/6/2026 | perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request. | |
| Modificada | Alta (7.5) | 1.2% | — | Valdersoft Shopping Cart | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the… | |
| Modificada | Media (4.3) | 1.0% | — | Valdersoft Shopping Cart | 28/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Igeneric Free Shopping Cart | 21/2/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Insite InmailInsite Inshop | 10/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Insite InmailInsite Inshop | 10/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop allows remote attackers to inject arbitrary web script or HTML via the screen parameter. | |
| Modificada | Media (6.8) | 2.2% | — | Quadcomm Q-shop | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | FrenoshopAI | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Cactusoft Cactushop | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Cactusoft Cactushop | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Quadcomm Q-shop | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp. | |
| Modificada | Media (4.3) | 1.2% | — | Jshop E-commerce Jshop Server | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | PhpshopAI | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg. |