Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

599 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode".
ModificadaAlta (7.5)1.0%—Inventorymanagementsystem Project Inventorymanagementsystem12/9/202217/6/2026
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".
ModificadaCrítica (9.8)28%—Fishbowlinventory Fishbowl19/8/202217/6/2026
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
ModificadaCrítica (9.8)0.81%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.'
ModificadaCrítica (9.8)0.83%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc.
ModificadaCrítica (9.8)0.83%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
ModificadaCrítica (9.8)0.91%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.
ModificadaCrítica (9.8)0.91%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
ModificadaCrítica (9.8)0.91%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.
ModificadaCrítica (9.8)0.89%—Inventorymanagementsystem Project Inventorymanagementsystem18/8/202217/6/2026
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.
ModificadaCrítica (9.8)1.0%—Glpi-project Glpi Inventory27/6/202217/6/2026
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection can be made using package deployment tasks. This issue has been…
ModificadaMedia (5.3)5.9%💥 ExploitGlpi-project Glpi Inventory20/6/202217/6/2026
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.
ModificadaCrítica (9.8)1.1%—Argie Simple Inventory System2/6/202229/7/2026
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
ModificadaAlta (7.2)1.0%—Argie Simple Inventory System2/6/202229/7/2026
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.
ModificadaAlta (8.8)1.5%💥 PoCEmcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+423/5/20229/7/2026
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows…
ModificadaCrítica (9.8)1.7%—Bdtask Multi Store Inventory Management System20/5/202217/6/2026
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
ModificadaAlta (7.5)1.5%—Bdtask Multi Store Inventory Management System20/5/202217/6/2026
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
ModificadaCrítica (9.8)1.1%—Pharmacy Sales AND Inventory System Project Pharmacy Sales AND Inventory System13/5/202217/6/2026
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
ModificadaMedia (6.5)0.30%—Hcltech Bigfix Inventory6/5/202217/6/2026
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
ModificadaMedia (6.5)0.36%—Hcltech Bigfix Inventory6/5/202217/6/2026
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaMedia (5)0.32%—Mini-inventory-and-sales-management-system Project Mini-inventory-and-sales-management-system4/3/202217/6/2026
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.
ModificadaAlta (7.5)1.7%—TraefikOracle Communications Unified Inventory Management17/2/202217/6/2026
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a…
ModificadaAlta (7.8)0.25%—Snowsoftware Snow Inventory Java Scanner16/2/202217/6/2026
A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0
ModificadaMedia (5.5)0.23%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+2011/2/202217/6/2026
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health…
Orbitaley — Vulnerabilidades