Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Pharmacy Sales AND Inventory System Project Pharmacy Sales AND Inventory System13/5/202217/6/2026
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
ModificadaMedia (6.1)0.88%—Karma Project Karma25/2/202217/6/2026
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
ModificadaMedia (6.1)15%💥 ExploitKarma Project Karma5/2/202217/6/2026
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
ModificadaCrítica (9.8)1.3%—Code-projects Pharmacy Management20/1/202217/6/2026
An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.
ModificadaCrítica (9.8)1.5%—Pharmacy Point OF Sale System Project Pharmacy Point OF Sale System29/10/202117/6/2026
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
ModificadaAlta (7.5)2.1%—Pharmacy Medical Store AND Sale Point Project Pharmacy Medical Store AND Sale Point2/6/202117/6/2026
The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.
ModificadaBaja (2.4)0.42%—Harman Hermes16/11/202017/6/2026
A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
ModificadaMedia (4.6)0.50%—Harman Hermes16/11/202017/6/2026
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
ModificadaBaja (2.4)0.42%—Harman Hermes16/11/202017/6/2026
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
ModificadaMedia (4.6)0.50%—Harman Hermes16/11/202017/6/2026
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
ModificadaBaja (2.4)0.42%—Harman Hermes16/11/202017/6/2026
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
ModificadaMedia (4.6)0.49%—Harman Hermes16/11/202017/6/2026
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information.
ModificadaCrítica (9.8)4.3%—Karma-mojo Project Karma-mojo2/4/202017/6/2026
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
ModificadaCrítica (9.8)1.7%—Marmaro Masqmail19/11/201916/6/2026
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
ModificadaAlta (8.8)6.5%💥 PoCHarman AMX Mvp5150 Firmware15/5/201917/6/2026
HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.
ModificadaMedia (6.5)1.5%—Jenkins Gearman4/4/201917/6/2026
A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModificadaMedia (6.5)1.3%—Jenkins Gearman4/4/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
ModificadaCrítica (9.8)2.8%—JCO Karma20/12/201817/6/2026
SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.
ModificadaCrítica (9.8)1.6%—Phptpoint Pharmacy Management System29/10/201817/6/2026
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
ModificadaBaja (3.3)1.7%💥 ExploitTeclib-edition Armadito Antivirus21/2/201817/6/2026
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters…
ModificadaCrítica (9.8)4.1%—Harman AMX Firmware22/1/201617/6/2026
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362.
ModificadaCrítica (9.8)4.7%—Harman AMX Firmware22/1/201617/6/2026
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984.
ModificadaMedia (5.4)0.27%—Inzeratyzdarma ADS Free. CZ Advert21/10/201417/6/2026
The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.66%💥 PoCPharmaguideline26/9/201417/6/2026
The Pharmaguideline (aka com.pharmaguideline) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.4)1.6%—Hsgroup Forzearmate3/3/201417/6/2026
The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-storage resources, by leveraging control over any Google syndication advertising domain.
Orbitaley — Vulnerabilidades