Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
364 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.65% | — | Sanchitkmr Shopping Website | 4/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.87% | — | Sanchitkmr Shopping Website | 29/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file forgot-password.php. The manipulation of the argument contact leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.87% | — | Sanchitkmr Shopping Website | 29/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.69% | — | Online Shopping System Advanced Project Online Shopping System Advanced | 20/6/2023 | 17/6/2026 | A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched… | |
| Modificada | Media (5.4) | 0.59% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 18/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.39% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 8/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions. | |
| Modificada | Crítica (9.8) | 0.75% | — | Shoppingfeed | 18/4/2023 | 17/6/2026 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There… | |
| Modificada | Crítica (9.8) | 0.82% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 7/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The… | |
| Modificada | Crítica (9.1) | 0.64% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 7/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This vulnerability affects unknown code of the file delete_user_query.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 30/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 22/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.72% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 19/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (5.3) | 0.55% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 16/3/2023 | 17/6/2026 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it… | |
| Modificada | Alta (8.8) | 0.26% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 23/1/2023 | 17/6/2026 | The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Media (6.1) | 0.50% | — | Clicshopping V3 | 5/12/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 29/11/2022 | 17/6/2026 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php. | |
| Modificada | Media (4.3) | 0.58% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 6/9/2022 | 17/6/2026 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options… | |
| Modificada | Crítica (9.8) | 0.85% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 25/8/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.83% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 20/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.60% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 15/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (6.5) | 1.4% | — | Peel Shopping | 15/6/2022 | 9/7/2026 | PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database. | |
| Modificada | Crítica (9.8) | 1.7% | — | Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system | 29/3/2022 | 17/6/2026 | An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products. | |
| Modificada | Alta (7.5) | 1.2% | — | Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system | 29/3/2022 | 17/6/2026 | An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php. | |
| Modificada | Alta (7.2) | 1.3% | — | DPL Sync Woocommerce Product Feed TO Google Shopping | 28/3/2022 | 17/6/2026 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard |