Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
614 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.67% | — | Inventory Management System Project Inventory Management System | 20/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file app/ajax/search_sell_paymen_report.php. The manipulation of the argument customer leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.74% | — | Inventory Management System Project Inventory Management System | 20/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0. This issue affects some unknown processing of the file app/action/edit_update.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Wpinventory WP Inventory Manager | 16/8/2023 | 17/6/2026 | The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Crítica (9.8) | 0.74% | — | Mayurik Inventory Management System | 7/8/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file ex_catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Mayurik Inventory Management System | 7/8/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file product_data.php.. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.61% | — | Mayurik Inventory Management System | 7/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.63% | — | Inventory Management System Project Inventory Management System | 6/8/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The associated identifier of this… | |
| Modificada | Crítica (9.8) | 0.50% | — | Inventory Management System Project Inventory Management System | 6/8/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the argument user_id leads to improper access controls. The attack can be initiated… | |
| Modificada | Crítica (9.8) | 0.63% | — | Inventory Management System Project Inventory Management System | 6/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-236217 was assigned… | |
| Modificada | Alta (7.8) | 0.21% | — | Pointware Easyinventory | 23/7/2023 | 17/6/2026 | A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-235193 was assigned to… | |
| Modificada | Media (5.4) | 1.1% | 💥 PoC | Inventorypress Project Inventorypress | 17/7/2023 | 17/6/2026 | The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. | |
| Modificada | Alta (8.1) | 0.35% | — | Wpinventory WP Inventory Manager | 27/6/2023 | 17/6/2026 | The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack | |
| Modificada | Alta (7.8) | 0.25% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 23/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.5) | 0.70% | — | Webbax Myinventory | 31/5/2023 | 17/6/2026 | Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack. | |
| Modificada | Media (6.1) | 0.46% | — | Wpinventory WP Inventory Manager | 8/5/2023 | 17/6/2026 | The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators. | |
| Modificada | Media (5.4) | 0.55% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 13/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.81% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 11/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file cust_transac.php. The manipulation of the argument phonenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.59% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 5/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/city/phone_number leads to cross site scripting. It is possible… | |
| Modificada | Media (6.1) | 0.60% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 1/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated… | |
| Modificada | Crítica (9.8) | 0.67% | — | Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System | 1/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.48% | — | Inventory Management System Project Inventory Management System | 10/2/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter. | |
| Modificada | Media (4.8) | 0.48% | — | Inventory Management System Project Inventory Management System | 10/2/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Client Name parameter. | |
| Modificada | Media (4.8) | 0.48% | — | Inventory Management System Project Inventory Management System | 10/2/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter. |