Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Turnkeywebtools Sunshop Shopping Cart | 22/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Turnkeywebtools Sunshop Shopping Cart | 19/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549. | |
| Modificada | Media (6.5) | 0.89% | — | Turnkey Solutions Sunshop Shopping Cart | 30/4/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 30/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549. | |
| Modificada | Media (6.4) | 1.0% | — | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation." | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 9/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 2/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Turnkey WEB Tools Sunshop Shopping Cart | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php. | |
| Modificada | Media (5.8) | 1.9% | 💥 Exploit | Turnkey Solutions Sunshop Shopping Cart | 1/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php. | |
| Modificada | Media (5) | 1.5% | — | Turnkey Solutions Sunshop Shopping Cart | 31/12/2005 | 16/6/2026 | Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it… | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Turnkey Solutions Sunshop Shopping Cart | 3/7/2002 | 16/6/2026 | Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration. |