Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 32% | — | Spa-cart Ecommerce CMS | 26/8/2023 | 22/9/2026 | A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to… | |
| Modificada | Baja (2) | 60% | — | Spa-cart Ecommerce CMS | 26/8/2023 | 22/9/2026 | A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.… | |
| Modificada | Media (6.1) | 0.34% | — | Activeitzone Active Ecommerce CMS | 4/7/2023 | 17/6/2026 | A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ecommerce/support_ticket of the component Create Ticket Page. The manipulation of the argument details with the input <script>alert(1)</script> leads to… | |
| Modificada | Crítica (9.8) | 2.1% | — | Soluzioneglobale Ecommerce CMS | 27/8/2020 | 17/6/2026 | SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php" | |
| Modificada | Crítica (9.8) | 2.2% | — | Webexcels Ecommerce CMS | 27/8/2020 | 17/6/2026 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. | |
| Modificada | Media (6.1) | 0.92% | — | Webexcels Ecommerce CMS | 27/8/2020 | 17/6/2026 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter. |