Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Pharmacy Sales AND Inventory System Project Pharmacy Sales AND Inventory System | 13/5/2022 | 17/6/2026 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=. | |
| Modificada | Media (6.1) | 0.88% | — | Karma Project Karma | 25/2/2022 | 17/6/2026 | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter. | |
| Modificada | Media (6.1) | 15% | 💥 Exploit | Karma Project Karma | 5/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. | |
| Modificada | Crítica (9.8) | 1.3% | — | Code-projects Pharmacy Management | 20/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pharmacy Point OF Sale System Project Pharmacy Point OF Sale System | 29/10/2021 | 17/6/2026 | An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php. | |
| Modificada | Alta (7.5) | 2.1% | — | Pharmacy Medical Store AND Sale Point Project Pharmacy Medical Store AND Sale Point | 2/6/2021 | 17/6/2026 | The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases. | |
| Modificada | Baja (2.4) | 0.42% | — | Harman Hermes | 16/11/2020 | 17/6/2026 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | |
| Modificada | Media (4.6) | 0.50% | — | Harman Hermes | 16/11/2020 | 17/6/2026 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information. | |
| Modificada | Baja (2.4) | 0.42% | — | Harman Hermes | 16/11/2020 | 17/6/2026 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | |
| Modificada | Media (4.6) | 0.50% | — | Harman Hermes | 16/11/2020 | 17/6/2026 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information. | |
| Modificada | Baja (2.4) | 0.42% | — | Harman Hermes | 16/11/2020 | 17/6/2026 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information. | |
| Modificada | Media (4.6) | 0.49% | — | Harman Hermes | 16/11/2020 | 17/6/2026 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information. | |
| Modificada | Crítica (9.8) | 4.3% | — | Karma-mojo Project Karma-mojo | 2/4/2020 | 17/6/2026 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. | |
| Modificada | Crítica (9.8) | 1.7% | — | Marmaro Masqmail | 19/11/2019 | 16/6/2026 | masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. | |
| Modificada | Alta (8.8) | 6.5% | 💥 PoC | Harman AMX Mvp5150 Firmware | 15/5/2019 | 17/6/2026 | HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Gearman | 4/4/2019 | 17/6/2026 | A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Gearman | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Crítica (9.8) | 2.8% | — | JCO Karma | 20/12/2018 | 17/6/2026 | SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Phptpoint Pharmacy Management System | 29/10/2018 | 17/6/2026 | PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. | |
| Modificada | Baja (3.3) | 1.7% | 💥 Exploit | Teclib-edition Armadito Antivirus | 21/2/2018 | 17/6/2026 | An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters… | |
| Modificada | Crítica (9.8) | 4.1% | — | Harman AMX Firmware | 22/1/2016 | 17/6/2026 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362. | |
| Modificada | Crítica (9.8) | 4.7% | — | Harman AMX Firmware | 22/1/2016 | 17/6/2026 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984. | |
| Modificada | Media (5.4) | 0.27% | — | Inzeratyzdarma ADS Free. CZ Advert | 21/10/2014 | 17/6/2026 | The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.66% | 💥 PoC | Pharmaguideline | 26/9/2014 | 17/6/2026 | The Pharmaguideline (aka com.pharmaguideline) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.4) | 1.6% | — | Hsgroup Forzearmate | 3/3/2014 | 17/6/2026 | The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain. |