Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.35% | — | Salesagility Suitecrm | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | Salesforce Tough-cookie | 1/7/2023 | 17/6/2026 | Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized. | |
| Modificada | Media (4.8) | 0.55% | — | Salesagility Suitecrm | 16/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. | |
| Modificada | Media (6.1) | 0.38% | — | Wpoperation Salert - Fake Sales Notification Woocommerce | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions. | |
| Modificada | Media (4.8) | 2.3% | 💥 Exploit | Sales Tracker Management System Project Sales Tracker Management System | 9/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The… | |
| Modificada | Alta (7.5) | 0.50% | — | Webbax Salesbooster | 30/5/2023 | 17/6/2026 | Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php. | |
| Modificada | Crítica (9.8) | 0.74% | — | Sales Tracker Management System Project Sales Tracker Management System | 11/4/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The… | |
| Modificada | Media (6.1) | 0.88% | — | Sales Tracker Management System Project Sales Tracker Management System | 10/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file. | |
| Modificada | Alta (7.5) | 1.4% | — | Sales Tracker Management System Project Sales Tracker Management System | 10/4/2023 | 17/6/2026 | An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint. | |
| Analizada | Media (4.8) | 0.39% | — | Saleswonder Webinarignition | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saleswonder.Biz Webinar ignition plugin <= 2.14.2 versions. | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes WC Sales Notification | 27/3/2023 | 17/6/2026 | The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Media (5.4) | 0.55% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 13/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.81% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 11/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file cust_transac.php. The manipulation of the argument phonenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Sales Tracker Management System Project Sales Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Sales Tracker Management System 1.0 and classified as critical. This vulnerability affects the function delete_client of the file classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Sales Tracker Management System Project Sales Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/clients/manage_client.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Sales Tracker Management System Project Sales Tracker Management System | 9/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Sales Tracker Management System 1.0. Affected by this issue is some unknown functionality of the file admin/clients/view_client.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The… | |
| Modificada | Media (6.1) | 0.56% | — | Phone Shop Sales Managements System Project Phone Shop Sales Managements System | 8/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vulnerability affects unknown code of the file /osms/assets/plugins/jquery-validation-1.11.1/demo/captcha/index.php of the component CAPTCHA Handler. The manipulation leads to cross site scripting. The… | |
| Modificada | Media (5.4) | 0.59% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 5/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/city/phone_number leads to cross site scripting. It is possible… | |
| Modificada | Media (6.1) | 0.60% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 1/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated… | |
| Modificada | Crítica (9.8) | 0.67% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 1/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 26% | — | Salesagility Suitecrm | 25/2/2023 | 17/6/2026 | Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9. | |
| Modificada | Alta (8.8) | 0.49% | — | Sales Tracker Management System Project Sales Tracker Management System | 24/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.54% | — | Sales Tracker Management System Project Sales Tracker Management System | 23/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/?page=user/manage_user of the component Edit User. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Alta (8.1) | 0.49% | — | Sales Tracker Management System Project Sales Tracker Management System | 22/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. Affected is an unknown function of the file admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack… | |
| Modificada | Media (6.1) | 0.53% | — | Simple Sales Management System Project Simple Sales Management System | 7/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 sales management system 1.0, allows attackers to execute arbitrary code via the product_name and product_price inputs in file print.php. |