Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Softtr Informatics E-commerce PackAI | 2/10/2026 | 2/10/2026 | Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Baja (2.1) | 0.39% | — | Jaygajera17 E-commerce-project-springbootAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to… | |
| Aplazada | Media (6.1) | 0.25% | — | Ideasoft Smart E-commerceAI | 11/9/2026 | 25/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0. | |
| Aplazada | Media (6.1) | 0.25% | — | Dayneks Software Industry AND Trade INC E-commerce PlatformAI | 28/8/2026 | 31/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (5.4) | 0.23% | — | Akilli Ticaret Software Technologies LTD E-commerce PackAI | 28/8/2026 | 2/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001. | |
| Aplazada | Media (4.3) | 0.28% | — | Softtr Informatics Technology Trading Limited E-commerce PackAI | 27/8/2026 | 28/8/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49. | |
| Aplazada | Alta (7.1) | 0.25% | — | Welcart E-commerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Welcart E-commerceAI | 6/8/2026 | 26/8/2026 | The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks. | |
| Aplazada | Alta (8.3) | 0.18% | — | Softtr Information Technology Trade LTD E-commerce PackAI | 30/7/2026 | 31/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49. | |
| Aplazada | Alta (8.2) | 0.44% | — | FTC Software IT Services FTC E-commerce Management PanelAI | 30/7/2026 | 30/7/2026 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2. | |
| Aplazada | Alta (7.5) | 0.42% | — | Ikas Technology INC E-commerceAI | 17/7/2026 | 17/7/2026 | Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Pizzafy E-commerce SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public… | |
| Aplazada | Media (6.1) | 0.25% | — | Akin Software E-commerceAI | 23/6/2026 | 23/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS. This issue affects e-Commerce: before 1.25.01.06. | |
| Aplazada | Media (5.5) | 0.28% | — | Sourcecodester Pizzafy E-commerce SystemAI | 3/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Akilli Commerce Software Technologies E-commerce WebsiteAI | 14/5/2026 | 17/6/2026 | Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Akilli Commerce Software Technologies E-commerce WebsiteAI | 14/5/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester E-commerce SiteAI | 24/3/2026 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (7.6) | 0.19% | — | Dokuzsoft Technology LTD E-commerce ProductAI | 26/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd. E-Commerce Product allows Reflected XSS. This issue affects E-Commerce Product: through 10122025. | |
| Analizada | Baja (2) | 0.25% | — | Detronetdip E-commerce | 20/2/2026 | 17/6/2026 | A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The… | |
| Analizada | Baja (2.1) | 0.36% | — | Detronetdip E-commerce | 20/2/2026 | 17/6/2026 | A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Management Module. Performing a manipulation of the argument ID results in authorization bypass. Remote exploitation of the attack is possible. The exploit has been released… | |
| Modificada | Media (6.3) | 0.27% | — | Farktor E-commerce Package | 12/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating User-Controlled Variables. This issue affects E-Commerce Package: through 27112025. | |
| Modificada | Media (6.1) | 0.23% | — | Farktor E-commerce Package | 12/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS). This issue affects E-Commerce Package: through 27112025. | |
| Modificada | Crítica (9.8) | 0.37% | — | Farktor E-commerce Package | 12/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection. This issue affects E-Commerce Package: through 27112025. | |
| Analizada | Media (5.5) | 0.60% | — | Detronetdip E-commerce | 8/2/2026 | 17/6/2026 | A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument email can lead to missing authentication. The attack can be executed remotely. The… | |
| Analizada | Media (5.5) | 0.48% | — | Detronetdip E-commerce | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of the argument File results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been… |