Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online Shopping SystemAI | 4/9/2026 | 8/9/2026 | A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Shopping SystemAI | 31/8/2026 | 2/9/2026 | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Shopping SystemAI | 31/8/2026 | 31/8/2026 | A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Shopping SystemAI | 25/8/2026 | 26/8/2026 | A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sumit_form.php. Such manipulation of the argument Success leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Shopping SystemAI | 17/8/2026 | 20/8/2026 | A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Shopping SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.59% | — | Adonesevangelista Agri-trading Online Shopping System | 21/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Product results in sql injection. The attack may be initiated remotely. The… | |
| Analizada | Crítica (9.8) | 0.43% | — | Indieka900 Online Shopping System | 8/1/2026 | 17/6/2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter. | |
| Analizada | Alta (8.7) | 0.56% | — | Puneethreddyhc Online Shopping System Advanced | 12/12/2025 | 17/6/2026 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by… | |
| Aplazada | Alta (8.2) | 0.25% | — | Indieka900 Online-shopping-system-phpAI | 27/10/2025 | 17/6/2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php. | |
| Modificada | Media (5.5) | 0.42% | — | Projectworlds Online Shopping System | 27/10/2025 | 17/6/2026 | A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_submit.php. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Puneethreddy Online Shopping System AdvancedAI | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization. | |
| Analizada | Media (5.5) | 0.48% | — | Projectworlds Online Shopping System | 27/9/2025 | 17/6/2026 | A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.56% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.4) | 0.27% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary… | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement. | |
| Analizada | Media (6.5) | 0.24% | — | Puneethreddyhc Online Shopping System Advanced | 28/8/2025 | 25/9/2026 | A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions. | |
| Analizada | Alta (7.7) | 0.25% | — | Puneethreddyhc Online Shopping System Advanced | 29/7/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter. | |
| Analizada | Media (5.5) | 0.45% | — | Adonesevangelista Agri-trading Online Shopping System | 8/7/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/suppliercontroller.php. The manipulation of the argument supplier leads to sql injection. It is possible to launch the attack remotely. The… |