Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Spa-cart CMSAI | 11/12/2025 | 28/9/2026 | SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to execute arbitrary code in… | |
| Modificada | Media (6.3) | 0.60% | — | Spa-cartcms | 18/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavioral discrepancy. It is possible to launch the attack remotely. The complexity… | |
| Modificada | Media (6.9) | 0.54% | — | Spa-cartcms | 18/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral workflow. The attack may be… | |
| Modificada | Alta (8.1) | 0.49% | — | Spa-cart | 12/10/2023 | 17/6/2026 | SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts. | |
| Modificada | Alta (8.8) | 0.54% | — | Spa-cart | 12/10/2023 | 17/6/2026 | SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status. | |
| Modificada | Baja (2.1) | 32% | — | Spa-cart Ecommerce CMS | 26/8/2023 | 22/9/2026 | A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to… | |
| Modificada | Baja (2) | 60% | — | Spa-cart Ecommerce CMS | 26/8/2023 | 22/9/2026 | A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.… | |
| Modificada | Alta (7.5) | 2.0% | — | Alan Ward A-cart | 26/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873. | |
| Modificada | Media (5) | 1.5% | — | Alan Ward A-cart | 12/6/2006 | 16/6/2026 | A-CART 2.0 stores the acart2_0.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain username and password information. | |
| Modificada | Alta (7.5) | 2.4% | — | Alan Ward A-cart | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Alan Ward A-cart | 29/3/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms. | |
| Modificada | Media (5) | 7.8% | — | Coxco Support A-cartCoxco Support MetacartCoxco Support Midicart ASPCoxco Support Midicart ASP Maxi+3 | 11/4/2003 | 16/6/2026 | MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database. |