Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.20%—Softtr Informatics E-commerce PackAI2/10/20262/10/2026
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaBaja (2.1)0.39%—Jaygajera17 E-commerce-project-springbootAI13/9/202616/9/2026
A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to…
AplazadaMedia (6.1)0.25%—Ideasoft Smart E-commerceAI11/9/202625/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0.
AplazadaMedia (6.1)0.25%—Dayneks Software Industry AND Trade INC E-commerce PlatformAI28/8/202631/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not…
AplazadaMedia (5.4)0.23%—Akilli Ticaret Software Technologies LTD E-commerce PackAI28/8/20262/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.
AplazadaMedia (4.3)0.28%—Softtr Informatics Technology Trading Limited E-commerce PackAI27/8/202628/8/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49.
AplazadaAlta (7.1)0.25%—Welcart E-commerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
AplazadaMedia (6.5)0.40%—Welcart E-commerceAI6/8/202626/8/2026
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
AplazadaAlta (8.3)0.18%—Softtr Information Technology Trade LTD E-commerce PackAI30/7/202631/7/2026
Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49.
AplazadaAlta (8.2)0.44%—FTC Software IT Services FTC E-commerce Management PanelAI30/7/202630/7/2026
Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.
AplazadaAlta (7.5)0.42%—Ikas Technology INC E-commerceAI17/7/202617/7/2026
Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.
AplazadaMedia (5.5)0.43%—Sourcecodester Pizzafy E-commerce SystemAI5/7/20266/7/2026
A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public…
AplazadaMedia (6.1)0.25%—Akin Software E-commerceAI23/6/202623/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS. This issue affects e-Commerce: before 1.25.01.06.
AplazadaMedia (5.5)0.28%—Sourcecodester Pizzafy E-commerce SystemAI3/6/202622/7/2026
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed…
AplazadaCrítica (9.8)0.43%—Akilli Commerce Software Technologies E-commerce WebsiteAI14/5/202617/6/2026
Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001.
AplazadaCrítica (9.8)0.36%—Akilli Commerce Software Technologies E-commerce WebsiteAI14/5/202630/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001.
AplazadaMedia (5.5)0.41%—Sourcecodester E-commerce SiteAI24/3/202617/6/2026
A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
AplazadaAlta (7.6)0.19%—Dokuzsoft Technology LTD E-commerce ProductAI26/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd. E-Commerce Product allows Reflected XSS. This issue affects E-Commerce Product: through 10122025.
AnalizadaBaja (2)0.25%—Detronetdip E-commerce20/2/202617/6/2026
A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The…
AnalizadaBaja (2.1)0.36%—Detronetdip E-commerce20/2/202617/6/2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Management Module. Performing a manipulation of the argument ID results in authorization bypass. Remote exploitation of the attack is possible. The exploit has been released…
ModificadaMedia (6.3)0.27%—Farktor E-commerce Package12/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating User-Controlled Variables. This issue affects E-Commerce Package: through 27112025.
ModificadaMedia (6.1)0.23%—Farktor E-commerce Package12/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS). This issue affects E-Commerce Package: through 27112025.
ModificadaCrítica (9.8)0.37%—Farktor E-commerce Package12/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection. This issue affects E-Commerce Package: through 27112025.
AnalizadaMedia (5.5)0.60%—Detronetdip E-commerce8/2/202617/6/2026
A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument email can lead to missing authentication. The attack can be executed remotely. The…
AnalizadaMedia (5.5)0.48%—Detronetdip E-commerce8/2/202617/6/2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of the argument File results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…