Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

614 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.48%—Inventory Management System Project Inventory Management System10/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.
ModificadaMedia (6.1)0.38%—Inventory System Project Inventory System20/1/202317/6/2026
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
ModificadaAlta (7.8)1.0%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.
ModificadaAlta (7.8)0.97%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+157/10/202217/6/2026
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
ModificadaCrítica (9.8)1.7%—10-strike Network Inventory Explorer23/9/202217/6/2026
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
ModificadaAlta (7.5)1.2%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "username", "password", etc.
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc.
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode".
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".
ModificadaCrítica (9.8)28%—Fishbowlinventory Fishbowl19/8/202217/6/2026
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
ModificadaCrítica (9.8)0.81%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.'
ModificadaCrítica (9.8)0.83%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc.
ModificadaCrítica (9.8)0.83%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
ModificadaCrítica (9.8)0.91%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.
ModificadaCrítica (9.8)0.91%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
ModificadaCrítica (9.8)0.91%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.
ModificadaCrítica (9.8)0.89%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.
ModificadaCrítica (9.8)1.0%—Glpi-project Glpi Inventory27/6/202217/6/2026
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection can be made using package deployment tasks. This issue has been…
ModificadaMedia (5.3)5.9%💥 ExploitGlpi-project Glpi Inventory20/6/202217/6/2026
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.
ModificadaCrítica (9.8)1.1%—Argie Simple Inventory System2/6/202229/7/2026
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
ModificadaAlta (7.2)1.0%—Argie Simple Inventory System2/6/202229/7/2026
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.
Orbitaley — Vulnerabilidades