Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Winston-dsouza Ecommerce-websiteAI | 30/11/2025 | 3/9/2026 | A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site… | |
| Analizada | Media (6.9) | 0.77% | — | Scriptandtools Ecommerce-website-in-php | 27/4/2025 | 17/6/2026 | A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.34% | — | Scriptandtools Ecommerce-website-in-php | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.3) | 0.99% | — | Scriptandtools Ecommerce-website-in-php | 14/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The… | |
| Analizada | Media (6.3) | 0.99% | — | Scriptandtools Ecommerce-website-in-php | 14/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack… | |
| Analizada | Media (5.3) | 0.54% | — | S-a-zhd Ecommerce-website-using-php | 6/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.54% | — | S-a-zhd Ecommerce-website-using-php | 6/3/2025 | 17/6/2026 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.57% | — | S-a-zhd Ecommerce-website-using-php | 6/3/2025 | 17/6/2026 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /customer_register.php. The manipulation of the argument name leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.49% | — | Ecommerce-website Project Ecommerce-website | 5/12/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ecommerce-website Project Ecommerce-website | 8/4/2022 | 17/6/2026 | Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 2.7% | — | Ecommerce-website Project Ecommerce-website | 8/4/2022 | 17/6/2026 | Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (4.8) | 0.99% | — | Ecommerce-website Project Ecommerce-website | 4/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field. | |
| Modificada | Alta (8.8) | 1.7% | — | Ecommerce-website Project Ecommerce-website | 4/4/2022 | 17/6/2026 | An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component. |