Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.38% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 19/7/2026 | 20/7/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 2/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Ecommerce SystempayAI | 13/5/2026 | 17/6/2026 | Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash… | |
| Aplazada | Baja (2.1) | 0.45% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 8/5/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 29/4/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 29/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 29/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 29/4/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible to launch the… | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 29/4/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from… | |
| Aplazada | Baja (2) | 0.38% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 29/4/2026 | 17/6/2026 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of the file /admin/ajax.php?action=delete_category. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?action=save_category. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/ajax.php?action=login2. The manipulation of the argument e-mail leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin/ajax.php?action=delete_menu. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made… |