Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 557 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.94% | — | Csdeshang Dsmall | 11/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument file_name leads to path traversal: '../filedir'. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.56% | — | Csdeshang Dsmall | 11/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The manipulation leads to improper access controls. The attack can be launched… | |
| Modificada | Alta (7.5) | 2.2% | — | Csdeshang Dsmall | 11/1/2024 | 17/6/2026 | A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.68% | — | Dsmall Project Dsmall | 4/4/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html. | |
| Modificada | Media (5.4) | 0.54% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI. | |
| Modificada | Media (6.1) | 0.68% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI. | |
| Modificada | Media (5.4) | 0.54% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box). | |
| Modificada | Alta (7.5) | 1.1% | — | Dsmall Project Dsmall | 25/3/2018 | 17/6/2026 | dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. | |
| Modificada | Media (6.1) | 0.68% | — | Dsmall Project Dsmall | 22/3/2018 | 17/6/2026 | dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html. |