Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.70%—Oracle Suitecommerce Advanced27/8/202017/6/2026
Vulnerability in SuiteCommerce Advanced (SCA) Sites component of Oracle NetSuite service. Supported versions that are affected are prior to 2020.1.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise NetSuite SCA. Successful attacks of this vulnerability can…
ModificadaMedia (5.4)0.74%—Oracle Suitecommerce Advanced27/8/202017/6/2026
Vulnerability in the SuiteCommerce Advanced (SCA) component of Oracle NetSuite service. Supported versions that are affected are Montblanc, Vinson, Elbrus, Kilimanjaro, Aconcagua, 2018.2, 2019.1, 2019.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise NetSuite…
ModificadaMedia (6.1)0.98%—Arastta Ecommerce30/6/201917/6/2026
Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI.
ModificadaMedia (6.5)0.94%—Custom T-shirt Ecommerce Script Project Custom T-shirt Ecommerce Script23/2/201917/6/2026
PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount.
ModificadaMedia (6.3)0.37%—Juunan06 Ecommerce8/8/201817/6/2026
An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.php that can add new users and add products.
ModificadaAlta (7.5)22%💥 ExploitThecartpress Ecommerce Shopping Cart29/12/201717/6/2026
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
ModificadaAlta (8.8)0.51%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
ModificadaCrítica (9.8)1.2%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
ModificadaMedia (6.1)0.69%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
ModificadaCrítica (9.8)1.2%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
ModificadaMedia (6.1)0.69%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
ModificadaMedia (6.1)0.69%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.
ModificadaMedia (6.1)0.69%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.
ModificadaMedia (6.1)0.69%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
ModificadaAlta (8.6)1.1%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
ModificadaCrítica (9.8)1.2%—PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce28/12/201717/6/2026
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitPHP Multivendor Ecommerce Project PHP Multivendor Ecommerce13/12/201717/6/2026
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
ModificadaCrítica (10)1.1%—Modified-shop Modified Ecommerce Shopsoftware25/4/201717/6/2026
www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.
ModificadaMedia (6.1)0.78%—Wp-ecommerce Easy WP Smtp24/4/201717/6/2026
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.
ModificadaCrítica (9.8)3.7%💥 ExploitModified Ecommerce Shopsoftware15/2/201717/6/2026
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.
ModificadaMedia (4.3)3.4%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the…
ModificadaMedia (4)9.1%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to…
ModificadaMedia (4.3)6.4%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,…
ModificadaAlta (7.5)39%💥 ExploitWeb-dorado Ecommerce WD20/3/201517/6/2026
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids in a displayproducts action to index.php.
ModificadaAlta (7.5)2.4%💥 ExploitEcommercemajor Project Ecommercemajor4/2/201517/6/2026
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) password parameter to __admin/index.php.