Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)32%—Spa-cart Ecommerce CMS26/8/202322/9/2026
A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to…
ModificadaBaja (2)60%—Spa-cart Ecommerce CMS26/8/202322/9/2026
A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.…
ModificadaMedia (6.1)0.34%—Activeitzone Active Ecommerce CMS4/7/202317/6/2026
A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ecommerce/support_ticket of the component Create Ticket Page. The manipulation of the argument details with the input <script>alert(1)</script> leads to…
ModificadaCrítica (9.8)2.1%—Soluzioneglobale Ecommerce CMS27/8/202017/6/2026
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
ModificadaCrítica (9.8)2.2%—Webexcels Ecommerce CMS27/8/202017/6/2026
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
ModificadaMedia (6.1)0.92%—Webexcels Ecommerce CMS27/8/202017/6/2026
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.