Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Mwopen E-commerce | 10/12/2007 | 16/6/2026 | SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Work System E-commerce | 3/11/2007 | 16/6/2026 | Unspecified vulnerability in WORK system e-commerce before 4.0.2 has unknown impact and attack vectors related to "Ajax pages." | |
| Modificada | Baja (3.5) | 0.84% | — | Drupal Asin Field ModuleDrupalDrupal E-commerce ModuleDrupal Fullname Field FOR CCK+6 | 22/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments… | |
| Modificada | Alta (10) | 2.2% | — | E-commerce Solutions Auction ScriptE-commerce Solutions Multi-vendor E-shop ScriptE-commerce Solutions Shopping Cart Script | 1/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password) parameters. NOTE: some of these details are obtained from… | |
| Modificada | Alta (9.3) | 4.0% | 💥 Exploit | Work System E-commerce | 13/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Jshop E-commerce Jshop Server | 13/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Shopstorenow E-commerce Shopping Cart | 9/1/2007 | 16/6/2026 | SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Laurent VAN DEN Reysen Work System E-commerce | 22/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions before 3.0.4, allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to (1) index.php, (2) module/forum/forum.php, (3) unspecified files under module/, and… | |
| Modificada | Alta (7.5) | 1.2% | — | Sitesoutlet E-commerce Kit-1 | 21/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in SitesOutlet E-commerce Kit-1 PayPal Edition allow remote attackers to execute arbitrary SQL commands via the (1) keyword or (2) cid parameter in (a) catalogue.asp, or the (3) pid parameter in (b) viewDetail.asp. | |
| Modificada | Alta (7.5) | 1.4% | — | WEB Inhabit A+ Store E-commerce | 17/11/2006 | 16/6/2026 | SQL injection vulnerability in browse.asp in A+ Store E-Commerce allows remote attackers to execute arbitrary SQL commands via the ParentID parameter. | |
| Modificada | Media (6.8) | 1.6% | — | WEB Inhabit A+ Store E-commerce | 17/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in account_login.asp in A+ Store E-Commerce allow remote attackers to inject arbitrary web script or HTML via the (1) username (txtUserName) and (2) password (txtPassword) parameters. NOTE: portions of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Sitexpress E-commerce System | 16/11/2006 | 16/6/2026 | SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Creasito E-commerce Content Manager | 7/11/2006 | 16/6/2026 | Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame parameter to (1) addnewcont.php, (2) adminpassw.php, (3) amministrazione.php, (4) artins.php, (5) bgcolor.php, (6) cancartcat.php, (7) canccat.php, (8) cancelart.php, (9)… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Wahm E-commerce PIE Cart PRO | 25/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to execute arbitrary PHP code via a URL in the Home_Path parameter. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Wahm E-commerce PIE Cart PRO | 25/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5) articles.php, (6) faqs.php, (7) guestbook.php, (8) catalog.php, (9)… | |
| Modificada | Baja (3.5) | 0.96% | — | Drupal E-commerce Module | 27/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | See-commerce | 14/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Cybershop ASP Ultimate E-commerce Script | 4/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Orjinweb E-commerce | 11/1/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE. | |
| Modificada | Media (4.3) | 1.2% | — | Colony CMSColony E-commerce CMSColony Enterprise CMSColony Government CMS | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Colony CMS 2.75 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Marmaraweb E-commerce | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Marmaraweb E-commerce | 16/12/2005 | 16/6/2026 | PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Alisveristr E-commerce | 8/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages. | |
| Modificada | Media (4.3) | 1.2% | — | Jshop E-commerce Jshop Server | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Nextplace E-commerce ASP Engine | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp. |