Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.33%—Online Store System CMSAI26/3/202617/6/2026
Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind…
ModificadaMedia (5.3)1.9%—Online Store System Project Online Store System1/10/201917/6/2026
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.
ModificadaAlta (7.5)1.4%—Online Store System Project Online Store System1/10/201917/6/2026
Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.
ModificadaMedia (6.1)1.2%—Online Store System Project Online Store System1/10/201917/6/2026
Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected.
ModificadaMedia (5.4)0.76%—Online Store System Project Online Store System1/10/201917/6/2026
Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable
ModificadaMedia (5.4)0.77%—Online Store System Project Online Store System1/10/201917/6/2026
Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.