Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

599 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.74%—Mayurik Inventory Management System7/8/202317/6/2026
A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file ex_catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.74%—Mayurik Inventory Management System7/8/202317/6/2026
A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file product_data.php.. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaAlta (7.5)0.61%—Mayurik Inventory Management System7/8/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.63%—Inventory Management System Project Inventory Management System6/8/202317/6/2026
A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The associated identifier of this…
ModificadaCrítica (9.8)0.50%—Inventory Management System Project Inventory Management System6/8/202317/6/2026
A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the argument user_id leads to improper access controls. The attack can be initiated…
ModificadaCrítica (9.8)0.63%—Inventory Management System Project Inventory Management System6/8/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-236217 was assigned…
ModificadaAlta (7.8)0.21%—Pointware Easyinventory23/7/202317/6/2026
A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-235193 was assigned to…
ModificadaMedia (5.4)1.1%💥 PoCInventorypress Project Inventorypress17/7/202317/6/2026
The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.1)0.35%—Wpinventory WP Inventory Manager27/6/202317/6/2026
The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack
ModificadaAlta (7.5)0.70%—Webbax Myinventory31/5/202317/6/2026
Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal information without restriction by performing a path traversal attack.
ModificadaMedia (6.1)0.46%—Wpinventory WP Inventory Manager8/5/202317/6/2026
The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
ModificadaMedia (5.4)0.55%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System13/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.81%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System11/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file cust_transac.php. The manipulation of the argument phonenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (5.4)0.59%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System5/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/city/phone_number leads to cross site scripting. It is possible…
ModificadaMedia (6.1)0.60%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System1/3/202317/6/2026
A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated…
ModificadaCrítica (9.8)0.67%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System1/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (4.8)0.48%—Inventory Management System Project Inventory Management System10/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.
ModificadaMedia (4.8)0.48%—Inventory Management System Project Inventory Management System10/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Client Name parameter.
ModificadaMedia (4.8)0.48%—Inventory Management System Project Inventory Management System10/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
ModificadaMedia (4.8)0.48%—Inventory Management System Project Inventory Management System10/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.
ModificadaMedia (6.1)0.38%—Inventory System Project Inventory System20/1/202317/6/2026
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
ModificadaCrítica (9.8)1.7%—10-strike Network Inventory Explorer23/9/202217/6/2026
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
ModificadaAlta (7.5)1.2%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "username", "password", etc.
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc.
Orbitaley — Vulnerabilidades