Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System30/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System22/3/202317/6/2026
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.72%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script19/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.55%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart16/3/202317/6/2026
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it…
ModificadaAlta (8.8)0.26%—Lightspeedhq Ecwid Ecommerce Shopping Cart14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
ModificadaMedia (5.4)0.53%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart23/1/202317/6/2026
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaMedia (6.1)0.50%—Clicshopping V35/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.
ModificadaCrítica (9.8)1.2%—Online-shopping-system-advanced Project Online-shopping-system-advanced29/11/202217/6/2026
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
ModificadaMedia (4.3)0.58%—Lightspeedhq Ecwid Ecommerce Shopping Cart6/9/202217/6/2026
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options…
ModificadaCrítica (9.8)0.85%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script25/8/202217/6/2026
A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has…
ModificadaAlta (8.8)0.83%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script20/8/202217/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.60%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script15/8/202217/6/2026
A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The…
ModificadaMedia (6.5)1.4%—Peel Shopping15/6/20229/7/2026
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database.
ModificadaCrítica (9.8)1.7%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
ModificadaAlta (7.5)1.2%—Puneethreddyhc Online-shopping-system Project Puneethreddyhc Online-shopping-system29/3/202217/6/2026
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
ModificadaAlta (7.2)1.3%—DPL Sync Woocommerce Product Feed TO Google Shopping28/3/202217/6/2026
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard
ModificadaCrítica (9.8)1.1%—Phpgurukul Online Shopping Portal18/2/202217/6/2026
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
ModificadaCrítica (9.8)0.97%—Projectworlds Online-shopping-webvsite-in-php23/1/202217/6/2026
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
ModificadaMedia (4.3)0.45%—Projectworlds Online Shopping System22/12/202117/6/2026
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
ModificadaCrítica (9.8)1.1%—Projectworlds Online Shopping System22/12/202117/6/2026
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
ModificadaMedia (4.8)0.62%—Shoppagewp Shop Page WP29/11/202117/6/2026
The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)0.58%—Shopping Portal Project Shopping Portal5/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in examples_support/editable_ajax.php, and the (3) PHP_SELF…
ModificadaAlta (7.5)1.5%—Phpgurukul Online Shopping Portal27/10/202117/6/2026
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
ModificadaCrítica (9.8)52%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
ModificadaAlta (7.5)10%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
Orbitaley — Vulnerabilidades