Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

364 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.65%—Sanchitkmr Shopping Website4/7/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)0.87%—Sanchitkmr Shopping Website29/6/202317/6/2026
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file forgot-password.php. The manipulation of the argument contact leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.87%—Sanchitkmr Shopping Website29/6/202317/6/2026
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.69%—Online Shopping System Advanced Project Online Shopping System Advanced20/6/202317/6/2026
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched…
ModificadaMedia (5.4)0.59%—Online-shopping-system-advanced Project Online-shopping-system-advanced18/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaMedia (5.4)0.39%—Lightspeedhq Ecwid Ecommerce Shopping Cart8/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions.
ModificadaCrítica (9.8)0.75%—Shoppingfeed18/4/202317/6/2026
Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There…
ModificadaCrítica (9.8)0.82%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System7/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The…
ModificadaCrítica (9.1)0.64%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System7/4/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This vulnerability affects unknown code of the file delete_user_query.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System30/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System22/3/202317/6/2026
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.72%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script19/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.55%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart16/3/202317/6/2026
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it…
ModificadaAlta (8.8)0.26%—Lightspeedhq Ecwid Ecommerce Shopping Cart14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
ModificadaMedia (5.4)0.53%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart23/1/202317/6/2026
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaMedia (6.1)0.50%—Clicshopping V35/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.
ModificadaCrítica (9.8)1.2%—Online-shopping-system-advanced Project Online-shopping-system-advanced29/11/202217/6/2026
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
ModificadaMedia (4.3)0.58%—Lightspeedhq Ecwid Ecommerce Shopping Cart6/9/202217/6/2026
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options…
ModificadaCrítica (9.8)0.85%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script25/8/202217/6/2026
A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has…
ModificadaAlta (8.8)0.83%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script20/8/202217/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.60%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script15/8/202217/6/2026
A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The…
ModificadaMedia (6.5)1.4%—Peel Shopping15/6/20229/7/2026
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database.
ModificadaCrítica (9.8)1.7%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
ModificadaAlta (7.5)1.2%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
ModificadaAlta (7.2)1.3%—DPL Sync Woocommerce Product Feed TO Google Shopping28/3/202217/6/2026
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard
Orbitaley — Vulnerabilidades