Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
599 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.22% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8) | 0.30% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Media (6.9) | 0.70% | — | Janobe Point OF Sales AND Inventory Management System | 20/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.37% | — | Siamonhasan Warehouse Inventory System | 4/8/2024 | 17/6/2026 | A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change_password.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.37% | — | Siamonhasan Warehouse Inventory System | 4/8/2024 | 17/6/2026 | A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.8) | 0.17% | — | Dell Inventory Collector | 31/7/2024 | 24/7/2026 | Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system. | |
| Modificada | Alta (8.8) | 0.46% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 22/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Modificada | Media (5.3) | 0.45% | — | Oretnom23 Simple Inventory Management System | 17/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php of the component Order Handler. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely.… | |
| Analizada | Alta (7.5) | 0.41% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3. | |
| Analizada | Media (5.3) | 0.61% | — | Argie Simple Inventory System | 19/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file updateproduct.php. The manipulation of the argument ITEM leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.49% | — | Argie Simple Inventory System | 19/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Inventory System 1.0. It has been classified as critical. This affects an unknown part of the file tableedit.php. The manipulation of the argument from/to leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.49% | — | Argie Simple Inventory System | 19/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file updateprice.php. The manipulation of the argument ITEM leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.1) | 0.48% | — | Argie Simple Inventory System | 19/5/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (6.9) | 0.37% | — | Argie Simple Inventory System | 19/5/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Inventory System 1.0. Affected is an unknown function of the file /tableedit.php#page=editprice. The manipulation of the argument itemnumber leads to cross-site request forgery. It is possible to launch the attack remotely. The… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Ukrsolution Barcode Scanner With Inventory AND Order ManagerAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3. | |
| Aplazada | Media (4.3) | 0.25% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.3) | 0.58% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Alta (8.8) | 0.61% | — | Barcode Scanner Inventory Manager POSAI | 2/5/2024 | 17/6/2026 | The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Media (5.3) | 0.58% | — | HCL Bigfix InventoryAI | 3/4/2024 | 17/6/2026 | The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file. |