Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.70% | — | Oracle Suitecommerce Advanced | 27/8/2020 | 17/6/2026 | Vulnerability in SuiteCommerce Advanced (SCA) Sites component of Oracle NetSuite service. Supported versions that are affected are prior to 2020.1.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise NetSuite SCA. Successful attacks of this vulnerability can… | |
| Modificada | Media (5.4) | 0.74% | — | Oracle Suitecommerce Advanced | 27/8/2020 | 17/6/2026 | Vulnerability in the SuiteCommerce Advanced (SCA) component of Oracle NetSuite service. Supported versions that are affected are Montblanc, Vinson, Elbrus, Kilimanjaro, Aconcagua, 2018.2, 2019.1, 2019.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise NetSuite… | |
| Modificada | Media (6.1) | 0.98% | — | Arastta Ecommerce | 30/6/2019 | 17/6/2026 | Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI. | |
| Modificada | Media (6.5) | 0.94% | — | Custom T-shirt Ecommerce Script Project Custom T-shirt Ecommerce Script | 23/2/2019 | 17/6/2026 | PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount. | |
| Modificada | Media (6.3) | 0.37% | — | Juunan06 Ecommerce | 8/8/2018 | 17/6/2026 | An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.php that can add new users and add products. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 29/12/2017 | 17/6/2026 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism." | |
| Modificada | Alta (8.8) | 0.51% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter. | |
| Modificada | Media (6.1) | 0.69% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter. | |
| Modificada | Media (6.1) | 0.69% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter. | |
| Modificada | Media (6.1) | 0.69% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter. | |
| Modificada | Media (6.1) | 0.69% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter. | |
| Modificada | Media (6.1) | 0.69% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. | |
| Modificada | Alta (8.6) | 1.1% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | |
| Modificada | Crítica (9.8) | 1.2% | — | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 28/12/2017 | 17/6/2026 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce | 13/12/2017 | 17/6/2026 | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | |
| Modificada | Crítica (10) | 1.1% | — | Modified-shop Modified Ecommerce Shopsoftware | 25/4/2017 | 17/6/2026 | www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php. | |
| Modificada | Media (6.1) | 0.78% | — | Wp-ecommerce Easy WP Smtp | 24/4/2017 | 17/6/2026 | XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Modified Ecommerce Shopsoftware | 15/2/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php. | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the… | |
| Modificada | Media (4) | 9.1% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to… | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,… | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Web-dorado Ecommerce WD | 20/3/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids in a displayproducts action to index.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Ecommercemajor Project Ecommercemajor | 4/2/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) password parameter to __admin/index.php. |