Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.59% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 18/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.2% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 29/11/2022 | 17/6/2026 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php. | |
| Modificada | Crítica (9.8) | 52% | 💥 Exploit | Online-shopping-system-advanced Project Online-shopping-system-advanced | 1/10/2021 | 17/6/2026 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Online-shopping-system-advanced Project Online-shopping-system-advanced | 1/10/2021 | 17/6/2026 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input. |