Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 7.5% | 💥 Exploit | Alex Heiphetz Group Ezshopper | 9/1/2001 | 16/6/2026 | loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter. | |
| Modificada | Media (5) | 1.1% | — | Dansie Shopping Cart | 31/12/2000 | 23/9/2026 | Fuga de privacidad en Dansie Shopping Cart 3.04, y probablemente versiones anteriores, envía información sensible como credenciales de usuario a una dirección de correo electrónico controlada por los desarrolladores del producto. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Bytes Interactive WEB Shopper | 19/12/2000 | 23/9/2026 | Vulnerabilidad de salto de directorio en el programa de carrito de compras Bytes Interactive Web Shopper (shopper.cgi) 2.0 y anteriores permite a atacantes remotos leer archivos arbitrarios mediante un ataque .. (punto punto) en el parámetro newpage. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Smartwin Technology Cyberoffice Shopping Cart | 19/12/2000 | 23/9/2026 | La instalación predeterminada de SmartWin CyberOffice Shopping Cart 2 (también conocido como CyberShop) instala el directorio _private con permisos de lectura para todos, lo que permite a atacantes remotos obtener información sensible. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Hassan Consulting Shopping Cart | 19/12/2000 | 23/9/2026 | Vulnerabilidad de salto de directorio en el programa de carrito de compras shop.cgi de Hassan Consulting permite a atacantes remotos leer archivos arbitrarios mediante un ataque de .. (punto punto) en el parámetro page. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Smartwin Technology Cyberoffice Shopping Cart | 19/12/2000 | 25/9/2026 | SmartWin CyberOffice Shopping Cart 2 (también conocido como CyberShop) permite a atacantes remotos modificar información de precios cambiando la variable de formulario oculta 'Price'. | |
| Modificada | Alta (7.5) | 1.6% | — | Element N.V Element Instantshop | 11/12/2000 | 23/9/2026 | add_2_basket.asp en Element InstantShop permite a atacantes remotos modificar información de precios a través de la variable de formulario oculta 'price'. | |
| Modificada | Alta (7.2) | 0.36% | — | SGI Workshop Debugger AND Performance Tools | 20/6/2000 | 16/6/2026 | Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files. | |
| Modificada | Alta (7.5) | 2.4% | — | Pdgsoft PDG Shopping Cart | 1/5/2000 | 16/6/2026 | Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Craig Dansie Dansie Shopping Cart | 14/4/2000 | 16/6/2026 | The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables. | |
| Modificada | Alta (10) | 2.5% | — | Craig Dansie Dansie Shopping Cart | 11/4/2000 | 16/6/2026 | The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields. | |
| Modificada | Media (5) | 2.2% | — | Craig Dansie Dansie Shopping Cart | 11/4/2000 | 16/6/2026 | The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable. | |
| Modificada | Alta (7.5) | 8.5% | 💥 Exploit | Alex Heiphetz Group Ezshopper | 27/2/2000 | 16/6/2026 | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | |
| Modificada | Alta (7.5) | 3.0% | — | Alex Heiphetz Group Ezshopper | 27/2/2000 | 16/6/2026 | EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | |
| Modificada | Baja (1.2) | 0.56% | 💥 Exploit | SUN Workshop | 21/2/2000 | 16/6/2026 | The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files. | |
| Modificada | Alta (7.5) | 2.1% | — | WEB Express Shoptron | 1/2/2000 | 16/6/2026 | The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | |
| Modificada | Alta (7.2) | 0.35% | — | Acushop Salesbuilder | 30/7/1999 | 16/6/2026 | .sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file. | |
| Modificada | Media (5) | 1.3% | — | Pdgsoft PDG Shopping Cart | 1/4/1999 | 16/6/2026 | An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information. |