Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

599 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.33%—Plainware PlaininventoryAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware PlainInventory z-inventory-manager allows Reflected XSS.This issue affects PlainInventory: from n/a through <= 3.1.5.
AplazadaCrítica (9.1)0.48%—Dmitry V Barcode Scanner With Inventory AND Order ManagerAI21/1/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Upload a Web Shell to a Web Server.This issue affects Barcode Scanner with Inventory & Order Manager:…
AplazadaMedia (6.1)0.29%—Wpinventory WP Inventory ManagerAI17/1/202517/6/2026
The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaMedia (5.3)0.52%—Campcodes Deped Equipment Inventory System9/1/202517/6/2026
A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /data/add_employee.php. The manipulation of the argument data leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
AplazadaAlta (8.1)0.43%—Plainware PlaininventoryAI7/1/202517/6/2026
Deserialization of Untrusted Data vulnerability in plainware PlainInventory z-inventory-manager allows Object Injection.This issue affects PlainInventory: from n/a through <= 3.1.6.
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System4/1/202517/6/2026
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/update_account.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (5.3)0.52%—Code-projects Point OF Sales AND Inventory Management System4/1/202517/6/2026
A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /user/search_num.php. The manipulation of the argument search leads to sql injection. The attack can be launched…
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management System 1.0. Affected is an unknown function of the file /user/minus_cart.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/search_result.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The…
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (5.3)0.45%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/add_cart.php. The manipulation of the argument id/qty leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (5.3)0.43%—Code-projects Point OF Sales AND Inventory Management System3/1/202517/6/2026
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /user/search_result2.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. It is possible to…
AnalizadaAlta (7.8)0.19%—Dell Inventory Collector18/12/202417/6/2026
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation of Privileges and unauthorized file system access.
AplazadaBaja (3.1)0.26%—HCL Bigfix InventoryAI17/12/202417/6/2026
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.
AplazadaAlta (7.1)0.44%—Dmitry V Barcode Scanner With Inventory AND Order ManagerAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Reflected XSS.This issue affects Barcode Scanner with Inventory…
AnalizadaMedia (5.3)0.72%—Code-projects Inventory Management15/11/202417/6/2026
A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /model/editProduct.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.41%—Mayurik Free AND Open Source Inventory Management System29/9/202417/6/2026
A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/action/add_staff.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.58%—Code-projects Inventory Management12/9/202417/6/2026
A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of the component Products Table Page. The manipulation of the argument id leads to sql injection. The attack can be launched…
AnalizadaMedia (6.9)0.56%—Code-projects Inventory Management9/9/202417/6/2026
A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration Form. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack can be…
AplazadaMedia (5.4)0.25%—Mini Inventory AND Sales Management SystemAI21/8/202417/6/2026
A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
AnalizadaAlta (8.8)0.30%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
AnalizadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
ModificadaAlta (8.8)0.31%—Siamonhasan Warehouse Inventory System20/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.