Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | PhpshopAI | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg. | |
| Modificada | Media (5) | 1.4% | — | Cassiopeia S-mart Shopping CartItransact Redicart | 31/12/2004 | 16/6/2026 | S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Fools Workshop Owls Workshop | 23/11/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en OWLS 1.0 permite a atacantes remotos leer ficheros de su elección mediante un .. (punto punto) en los parámetros (1) file en index.php, (2) editfile en glossary.php, o (3) editfile en newmultiplechoice.php. | |
| Modificada | Media (5) | 1.4% | — | Cactusoft Cactushop Lite | 23/11/2004 | 16/6/2026 | La función AddToMailingList en CactuSoft 5.0 Lite contiene una puerta trasera que permite a atacantes remotos borrar ficheros de su elección mediante una dirección de correo electrónico que comience con ||| (tres barras verticales). | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | Shopcartcgi | 23/11/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directoros en ShopCartCGI 2.3 permite a atacantes remotos obtener ficheros de su elección mediante un .. (punto punto) en una petición HTTP a (1) gotopage.cgi, o (2) genindexpage.cgi. | |
| Modificada | Media (4.3) | 1.4% | — | Jshop E-commerce Jshop ProfessionalJshop E-commerce Jshop Server | 7/2/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Urlogy A.shop.kart | 31/12/2003 | 16/6/2026 | Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters. | |
| Modificada | Media (4.3) | 1.3% | — | Ecw-shop | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Julien Desaunay Phpmyshop | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters. | |
| Modificada | Media (5) | 2.0% | 💥 Exploit | Dansie Shopping Cart | 31/12/2003 | 16/6/2026 | cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message. | |
| Modificada | Alta (10) | 5.9% | 💥 Exploit | Cyberstrong Eshop | 7/8/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Cyberstrong eShop 4.2 y anteriores permite a atacantes remotos robar información de autenticación y ganar privilegios mediante el parámetro ProductCode en (1) 10expand.asp, (2) 10browse.asp, y (3) 20review.asp. | |
| Modificada | Alta (7.5) | 2.4% | — | Webscriptworld WEB Shop Manager | 9/6/2003 | 16/6/2026 | Web Shop Manager 1.1 permite a atacantes remotos la ejecución arbitraria de comandos mediante la utilización de metacaracteres de shell en la caja de búsqueda. | |
| Modificada | Alta (7.5) | 1.2% | — | Thorsten Korner 123tkshop | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php. | |
| Modificada | Media (4.3) | 1.2% | — | Cows CGI Online Worldweb Shopping | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CGI Online Worldweb Shopping 1.1 (a.k.a. COWS) allows remote attackers to execute arbitrary script as other users by injecting script into (1) diagnose.cgi or (2) compatible.cgi. | |
| Modificada | Media (6.4) | 1.2% | — | 3d3.com Shopfactory | 31/12/2002 | 16/6/2026 | 3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field. | |
| Modificada | Alta (7.8) | 1.0% | — | 3d3.com Shopfactory | 31/12/2002 | 16/6/2026 | 3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data. | |
| Modificada | Media (5) | 1.7% | — | Thorsten Korner 123tkshop | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call. | |
| Modificada | Media (5) | 2.0% | 💥 Exploit | Dcscripts Dcshop | 12/8/2002 | 16/6/2026 | dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Caupo.net Cauposhop | 26/7/2002 | 16/6/2026 | Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Turnkey Solutions Sunshop Shopping Cart | 3/7/2002 | 16/6/2026 | Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | Dcscripts Dcshop | 6/12/2001 | 16/6/2026 | The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt. | |
| Modificada | Alta (7.5) | 2.3% | — | Michael Boehme Webdiscount E Shop Online Shop System | 15/9/2001 | 16/6/2026 | eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Hassan Consulting Shopping Cart | 8/9/2001 | 16/6/2026 | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Kabotie Software Technologies Shopplus Cart | 5/9/2001 | 16/6/2026 | shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Microburst Ustorekeeper Online Shopping System | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. |