Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Pizzafy E-commerce SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public… | |
| Aplazada | Media (5.5) | 0.28% | — | Sourcecodester Pizzafy E-commerce SystemAI | 3/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed… | |
| Analizada | Media (5.3) | 0.70% | — | Janobe E-commerce System | 23/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.60% | — | Janobe E-commerce System | 22/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.69% | — | Janobe E-commerce System | 22/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the component Admin Login. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The… | |
| Modificada | Media (5.4) | 0.49% | — | E-commerce System Project E-commerce System | 22/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester E-Commerce System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/user/controller.php?action=edit. The manipulation of the argument U_NAME with the input <script>alert('1')</script> leads to cross site scripting.… | |
| Modificada | Crítica (9.8) | 0.46% | — | E-commerce System Project E-commerce System | 22/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ecommerce/admin/user/controller.php?action=edit of the component Username Handler. The manipulation of the argument USERID leads to improper access… | |
| Modificada | Media (6.1) | 0.36% | — | E-commerce System Project E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ecommerce/admin/category/controller.php of the component Category Name Handler. The manipulation of the argument CATEGORY leads to cross site… | |
| Modificada | Alta (8.1) | 0.51% | — | E-commerce System Project E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester E-Commerce System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The… | |
| Modificada | Alta (8.1) | 0.55% | — | E-commerce System Project E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester E-Commerce System 1.0. This issue affects some unknown processing of the file /ecommerce/admin/settings/setDiscount.php. The manipulation of the argument id with the input 201737 AND (SELECT 8973 FROM (SELECT(SLEEP(5)))OoAD) leads to… | |
| Modificada | Alta (8.1) | 0.61% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. This vulnerability affects unknown code. The manipulation of the argument email/password with the input test1%40test.com ' AND (SELECT 6077 FROM (SELECT(SLEEP(5)))dltn) AND 'PhRa'='PhRa leads to sql injection.… | |
| Modificada | Alta (8.1) | 0.61% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file admin/admin_index.php. The manipulation of the argument username/password with the input admin' AND (SELECT 8062 FROM (SELECT(SLEEP(5)))meUD)-- hLiX leads to sql… | |
| Modificada | Alta (8.1) | 0.61% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 20/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file function/edit_customer.php. The manipulation of the argument firstname/mi/lastname with the input a' RLIKE SLEEP(5) AND 'dAbu'='dAbu leads… | |
| Modificada | Crítica (9.8) | 0.75% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 19/3/2023 | 17/6/2026 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. | |
| Modificada | Media (5.3) | 0.91% | — | Alphaware Simple E-commerce System Project Alphaware Simple E-commerce System | 24/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access controls. It is possible to initiate the… | |
| Modificada | Alta (8.8) | 0.91% | — | Moosikay E-commerce System Project Moosikay E-commerce System | 24/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be… | |
| Modificada | Media (5.4) | 0.59% | — | Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System | 5/8/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. Affected by this issue is some unknown functionality of the file stockin.php. The manipulation of the argument id with the input '"><script>alert(/xss/)</script> leads to cross site scripting. The… | |
| Modificada | Alta (8.8) | 0.85% | — | Alphaware E-commerce System Project Alphaware E-commerce System | 5/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown code of the file admin_feature.php of the component Background Management Page. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The… | |
| Modificada | Media (6.5) | 0.47% | — | EC Cloud E-commerce System Project EC Cloud E-commerce System | 4/11/2021 | 17/6/2026 | EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add. | |
| Modificada | Alta (7.5) | 2.3% | — | Martin LEE Multi-lingual E-commerce System | 3/9/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) checkout2-CYM.php, (2) checkout2-EN.php, (3) checkout2-FR.php, (4) cat-FR.php, (5) cat-EN.php, (6) cat-CYM.php, (7)… | |
| Modificada | Alta (7.5) | 1.2% | — | Sitexpress E-commerce System | 16/11/2006 | 16/6/2026 | SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter. |