Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.43%—Sourcecodester Pizzafy E-commerce SystemAI5/7/20266/7/2026
A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public…
AplazadaMedia (5.5)0.28%—Sourcecodester Pizzafy E-commerce SystemAI3/6/202622/7/2026
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed…
AnalizadaMedia (5.3)0.70%—Janobe E-commerce System23/8/202417/6/2026
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.60%—Janobe E-commerce System22/8/202417/6/2026
A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.69%—Janobe E-commerce System22/8/202417/6/2026
A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the component Admin Login. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The…
ModificadaMedia (5.4)0.49%—E-commerce System Project E-commerce System22/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester E-Commerce System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/user/controller.php?action=edit. The manipulation of the argument U_NAME with the input <script>alert('1')</script> leads to cross site scripting.…
ModificadaCrítica (9.8)0.46%—E-commerce System Project E-commerce System22/3/202317/6/2026
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ecommerce/admin/user/controller.php?action=edit of the component Username Handler. The manipulation of the argument USERID leads to improper access…
ModificadaMedia (6.1)0.36%—E-commerce System Project E-commerce System20/3/202317/6/2026
A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ecommerce/admin/category/controller.php of the component Category Name Handler. The manipulation of the argument CATEGORY leads to cross site…
ModificadaAlta (8.1)0.51%—E-commerce System Project E-commerce System20/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester E-Commerce System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The…
ModificadaAlta (8.1)0.55%—E-commerce System Project E-commerce System20/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester E-Commerce System 1.0. This issue affects some unknown processing of the file /ecommerce/admin/settings/setDiscount.php. The manipulation of the argument id with the input 201737 AND (SELECT 8973 FROM (SELECT(SLEEP(5)))OoAD) leads to…
ModificadaAlta (8.1)0.61%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System20/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. This vulnerability affects unknown code. The manipulation of the argument email/password with the input test1%40test.com ' AND (SELECT 6077 FROM (SELECT(SLEEP(5)))dltn) AND 'PhRa'='PhRa leads to sql injection.…
ModificadaAlta (8.1)0.61%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System20/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file admin/admin_index.php. The manipulation of the argument username/password with the input admin' AND (SELECT 8062 FROM (SELECT(SLEEP(5)))meUD)-- hLiX leads to sql…
ModificadaAlta (8.1)0.61%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System20/3/202317/6/2026
A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file function/edit_customer.php. The manipulation of the argument firstname/mi/lastname with the input a' RLIKE SLEEP(5) AND 'dAbu'='dAbu leads…
ModificadaCrítica (9.8)0.75%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System19/3/202317/6/2026
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.
ModificadaMedia (5.3)0.91%—Alphaware Simple E-commerce System Project Alphaware Simple E-commerce System24/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argument amount leads to improper access controls. It is possible to initiate the…
ModificadaAlta (8.8)0.91%—Moosikay E-commerce System Project Moosikay E-commerce System24/2/202317/6/2026
A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be…
ModificadaMedia (5.4)0.59%—Alphaware - Simple E-commerce System Project Alphaware - Simple E-commerce System5/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. Affected by this issue is some unknown functionality of the file stockin.php. The manipulation of the argument id with the input '"><script>alert(/xss/)</script> leads to cross site scripting. The…
ModificadaAlta (8.8)0.85%—Alphaware E-commerce System Project Alphaware E-commerce System5/8/202217/6/2026
A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown code of the file admin_feature.php of the component Background Management Page. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The…
ModificadaMedia (6.5)0.47%—EC Cloud E-commerce System Project EC Cloud E-commerce System4/11/202117/6/2026
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
ModificadaAlta (7.5)2.3%—Martin LEE Multi-lingual E-commerce System3/9/201016/6/2026
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) checkout2-CYM.php, (2) checkout2-EN.php, (3) checkout2-FR.php, (4) cat-FR.php, (5) cat-EN.php, (6) cat-CYM.php, (7)…
ModificadaAlta (7.5)1.2%—Sitexpress E-commerce System16/11/200616/6/2026
SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.