Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Stock Management SystemAI | 23/8/2026 | 26/8/2026 | A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Stock Management SystemAI | 23/8/2026 | 24/8/2026 | A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Stock Management SystemAI | 16/8/2026 | 20/8/2026 | A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Ingredients Stock Management SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Ingredients Stock Management SystemAI | 1/6/2026 | 22/7/2026 | A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been published and may… | |
| Aplazada | Baja (2.1) | 0.23% | — | Haxxorsid Stock-management-systemAI | 12/12/2025 | 7/10/2026 | A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This impacts an unknown function of the file model/User.php. The manipulation of the argument employee_id/id/admin leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.5) | 0.77% | — | Haxxorsid Stock-management-system | 12/12/2025 | 7/10/2026 | A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This affects an unknown function of the file /api/employees. Executing manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been made available… | |
| Analizada | Media (6.9) | 0.51% | — | Oretnom23 Stock Management System | 19/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 Stock Management System | 16/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=back_order/view_bo. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.49% | — | Oretnom23 Stock Management System | 16/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /admin/?page=sales/view_sale. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.50% | — | Oretnom23 Stock Management System | 16/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/?page=return/view_return. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.61% | — | Oretnom23 Stock Management System | 16/5/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.66% | — | Oretnom23 Stock Management System | 5/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.35% | — | Oretnom23 Stock Management System | 5/5/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.1) | 0.49% | — | Oretnom23 Stock Management System | 5/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to… | |
| Modificada | Media (6.9) | 0.66% | — | Warrendaloyan Stock Management System | 9/6/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Stock Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.57% | — | Stock Management System Project Stock Management System | 6/6/2024 | 17/6/2026 | Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php. | |
| Analizada | Media (5.3) | 0.64% | — | Warrendaloyan Stock Management System | 30/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Stock Management System 1.0. It has been classified as critical. Affected is an unknown function of the file createBrand.php. The manipulation of the argument brandName leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 1.4% | — | Stock Management System Project Stock Management System | 5/2/2024 | 17/6/2026 | SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. | |
| Modificada | Media (5.4) | 0.56% | — | Swapnilsahu Stock Management System | 27/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to cross site scripting. The attack may be… | |
| Modificada | Alta (8.8) | 0.26% | — | Stock Management System Project Stock Management System | 24/11/2022 | 17/6/2026 | A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (5.4) | 0.40% | — | Stock Management System Project Stock Management System | 24/11/2022 | 17/6/2026 | A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.60% | — | Stock Management System Project Stock Management System | 24/11/2022 | 17/6/2026 | A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.98% | — | Ingredient Stock Management System Project Ingredient Stock Management System | 29/8/2022 | 17/6/2026 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=. | |
| Modificada | Alta (8.8) | 1.0% | — | Ingredient Stock Management System Project Ingredient Stock Management System | 29/8/2022 | 17/6/2026 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=. |