Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.56%—Puneethreddyhc Online Shopping System Advanced12/12/202517/6/2026
Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by…
AplazadaCrítica (9.8)0.33%—Puneethreddy Online Shopping System AdvancedAI7/10/202517/6/2026
A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization.
AnalizadaMedia (6.5)0.24%—Puneethreddyhc Online Shopping System Advanced28/8/202525/9/2026
A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
AnalizadaMedia (5.4)0.27%—Puneethreddyhc Online Shopping System Advanced28/8/202525/9/2026
A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary…
AnalizadaMedia (6.5)0.24%—Puneethreddyhc Online Shopping System Advanced28/8/202525/9/2026
A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement.
AnalizadaMedia (6.5)0.24%—Puneethreddyhc Online Shopping System Advanced28/8/202525/9/2026
A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions.
AnalizadaAlta (7.7)0.25%—Puneethreddyhc Online Shopping System Advanced29/7/202517/6/2026
A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
AplazadaMedia (6.1)0.27%—Online Shopping System AdvancedAI14/5/202417/6/2026
Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.
ModificadaCrítica (9.8)0.69%—Online Shopping System Advanced Project Online Shopping System Advanced20/6/202317/6/2026
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched…
ModificadaMedia (5.4)0.59%—Online-shopping-system-advanced Project Online-shopping-system-advanced18/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaCrítica (9.8)1.2%—Online-shopping-system-advanced Project Online-shopping-system-advanced29/11/202217/6/2026
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
ModificadaCrítica (9.8)52%—Online-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
ModificadaAlta (7.5)10%—Online-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.