Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Netshinesoftware COM Netinvoice | 24/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the nBill (com_nbill) component 2.3.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the message parameter in an income action to administrator/index.php. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Simple Invoices | 28/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the Customer Name field in an Add Customer… | |
| Modificada | Alta (7.5) | 1.3% | — | Thomas Hunter Neoinvoice | 26/8/2012 | 16/6/2026 | SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477. | |
| Modificada | Alta (7.5) | 1.2% | — | Thomas Hunter Neoinvoice | 26/8/2012 | 16/6/2026 | SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands via the value parameter in a username action. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Chillcreations COM Ccinvoices | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Netshinesoftware COM Netinvoice | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving "knowledge of ... the contents of an encrypted file." | |
| Modificada | Media (5) | 1.8% | — | Netshinesoftware COM Netinvoice | 17/11/2010 | 16/6/2026 | Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1)… | |
| Modificada | Media (6.5) | 2.0% | 💥 Exploit | Cale Dunlap Openinvoice | 25/3/2009 | 16/6/2026 | resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Cale Dunlap Openinvoice | 25/3/2009 | 16/6/2026 | auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Netshinesoftware COM Netinvoice | 6/8/2008 | 16/6/2026 | SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Simple Invoices | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action. | |
| Modificada | Media (5) | 1.3% | — | Simple Invoices | 8/3/2007 | 16/6/2026 | include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information. | |
| Modificada | Media (6.8) | 1.8% | — | Simple Invoices | 6/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.3% | — | PHP Invoice | 3/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2006-5074. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | PHP Invoice | 29/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ezinvoiceinc EZ Invoice INC | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email support@ezinvoiceinc.com and EZI will email you the patch to fix this small issue." |