Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Analizada | Media (6.1) | 0.26% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to inject arbitrary web… | |
| Analizada | Crítica (9.3) | 0.88% | — | Ftnapps Crashmail II | 28/3/2026 | 7/10/2026 | Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of… | |
| Analizada | Media (4.8) | 0.30% | — | Ahsanriaz26gmailcom Inventory System | 27/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the view_purchase.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Inventory System | 27/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Inventory System | 27/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Inventory System | 27/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_sales.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Inventory System | 27/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_stock_availability.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via… | |
| Analizada | Baja (2.3) | 0.57% | — | Rubyonrails Rails | 26/3/2026 | 17/6/2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU usage compared to a… | |
| Analizada | Baja (1.3) | 0.26% | — | Sakailms Sakai | 26/3/2026 | 17/6/2026 | Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions… | |
| Analizada | Baja (2.1) | 0.47% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 26/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Baja (2.1) | 0.37% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 25/3/2026 | 17/6/2026 | A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /update_sales.php of the component HTTP GET Parameter Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.5) | 0.42% | — | Noor Alam Smtp MailerAI | 25/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Embedded Sensitive Data.This issue affects SMTP Mailer: from n/a through <= 1.1.24. | |
| Aplazada | Media (6.5) | 0.33% | — | Codepeople Contact Form EmailAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.63. | |
| Aplazada | Media (6.5) | 0.34% | — | Crmperks Integration FOR Mailchimp AND Contact Form 7AI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a… | |
| Aplazada | Crítica (9.8) | 0.38% | — | Park OF Ideas Tasty DailyAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27. | |
| Analizada | Baja (2.1) | 0.47% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 25/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Sales and Inventory System 1.0. The affected element is an unknown function of the file update_purchase.php of the component HTTP GET Parameter Handler. Executing a manipulation of the argument sid can lead to sql injection. The attack may be performed from remote. The exploit… | |
| Analizada | Baja (2.1) | 0.47% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 25/3/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Sales and Inventory System 1.0. Impacted is an unknown function of the file update_out_standing.php of the component HTTP GET Parameter Handler. Performing a manipulation of the argument sid results in sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Baja (2.1) | 0.47% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 24/3/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unknown processing of the file update_customer_details.php of the component HTTP GET Parameter Handler. Such manipulation of the argument sid leads to sql injection. The attack can be executed remotely.… | |
| Analizada | Baja (2.1) | 0.37% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 24/3/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file update_category.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Analizada | Baja (2.1) | 0.37% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 24/3/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file view_supplier.php of the component POST Parameter Handler. The manipulation of the argument searchtxt results in sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.3) | 0.91% | — | Tabslab Mailcarrier | 24/3/2026 | 17/6/2026 | Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to… | |
| Analizada | Media (6.6) | 0.78% | — | Rubyonrails Rails | 24/3/2026 | 17/6/2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or… | |
| Modificada | Alta (8) | 0.72% | — | Rubyonrails Rails | 24/3/2026 | 15/7/2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences… | |
| Analizada | Media (6.6) | 0.97% | — | Rubyonrails Rails | 24/3/2026 | 17/6/2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely large decimal… |