Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
614 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.58% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Alta (8.8) | 0.61% | — | Barcode Scanner Inventory Manager POSAI | 2/5/2024 | 17/6/2026 | The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Media (5.3) | 0.58% | — | HCL Bigfix InventoryAI | 3/4/2024 | 17/6/2026 | The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file. | |
| Analizada | Media (5.4) | 0.55% | — | Bdtask Multi Store Inventory Management System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Store Update Page. The manipulation of the argument Store Name/Store Address leads to cross site scripting. The attack may… | |
| Analizada | Media (5.4) | 1.2% | 💥 PoC | Bdtask Multi Store Inventory Management System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Name/Unit Name leads to cross site scripting. The attack can be… | |
| Analizada | Media (4.8) | 0.52% | — | Bdtask Multi Store Inventory Management System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been classified as problematic. Affected is an unknown function of the component Page Title Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.38% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Aplazada | Media (4.3) | 0.55% | — | Bdtask Wholesale Inventory Management SystemAI | 19/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Wholesale Inventory Management System up to 20240311. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Alta (8) | 0.45% | — | Ciena Blue Planet Inventory | 6/3/2024 | 17/6/2026 | In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue… | |
| Analizada | Media (6.1) | 2.5% | — | Remyandrade Computer Inventory System | 1/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/update-computer.php. The manipulation of the argument model leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.48% | — | Remyandrade Computer Inventory System | 1/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. The manipulation of the argument computer leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.39% | — | Remyandrade Computer Inventory System | 1/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-computer.php. The manipulation of the argument model leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.63% | — | Mayurik Free AND Open Source Inventory Management System | 27/2/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated… | |
| Modificada | Media (5.5) | 0.12% | — | Snowsoftware Snow Inventory Agent | 8/2/2024 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1. | |
| Modificada | Media (5.5) | 0.12% | — | Snowsoftware Snow Inventory Agent | 8/2/2024 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through… | |
| Modificada | Media (5.5) | 0.16% | — | Snowsoftware Snow Inventory Agent | 8/2/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0 | |
| Modificada | Media (6.5) | 0.35% | — | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 30/1/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component. | |
| Modificada | Media (6.1) | 0.66% | 💥 PoC | Remyandrade Product Inventory With Export TO Excel | 29/1/2024 | 17/6/2026 | Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks. | |
| Modificada | Crítica (9.8) | 0.63% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 24/1/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1. | |
| Modificada | Media (5.4) | 0.50% | — | Codeastro POS AND Inventory Management System | 11/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /new_item of the component New Item Creation Page. The manipulation of the argument new_item leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 0.55% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For… | |
| Modificada | Media (6.9) | 0.63% | — | Ocsinventory-ng Ocsinventory-ocsreports | 4/1/2024 | 17/6/2026 | OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting. | |
| Modificada | Crítica (9.8) | 0.66% | — | Mayurik Free AND Open Source Inventory Management System | 29/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /app/ajax/sell_return_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack may be initiated… | |
| Modificada | Alta (8.8) | 0.63% | — | Mayurik Free AND Open Source Inventory Management System | 29/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Free and Open Source Inventory Management System 1.0. This affects an unknown part of the file /ample/app/action/edit_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Media (6.1) | 0.53% | — | Code-projects Point OF Sales AND Inventory Management System | 22/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The… |