Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
599 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 12/9/2022 | 17/6/2026 | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode". | |
| Modificada | Alta (7.5) | 1.0% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 12/9/2022 | 17/6/2026 | A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt". | |
| Modificada | Crítica (9.8) | 28% | — | Fishbowlinventory Fishbowl | 19/8/2022 | 17/6/2026 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload. | |
| Modificada | Crítica (9.8) | 0.81% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.' | |
| Modificada | Crítica (9.8) | 0.83% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc. | |
| Modificada | Crítica (9.8) | 0.83% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. | |
| Modificada | Crítica (9.8) | 0.91% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user. | |
| Modificada | Crítica (9.8) | 0.91% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. | |
| Modificada | Crítica (9.8) | 0.91% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode. | |
| Modificada | Crítica (9.8) | 0.89% | — | Inventorymanagementsystem Project Inventorymanagementsystem | 18/8/2022 | 17/6/2026 | A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username. | |
| Modificada | Crítica (9.8) | 1.0% | — | Glpi-project Glpi Inventory | 27/6/2022 | 17/6/2026 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection can be made using package deployment tasks. This issue has been… | |
| Modificada | Media (5.3) | 5.9% | 💥 Exploit | Glpi-project Glpi Inventory | 20/6/2022 | 17/6/2026 | ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used. | |
| Modificada | Crítica (9.8) | 1.1% | — | Argie Simple Inventory System | 2/6/2022 | 29/7/2026 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php. | |
| Modificada | Alta (7.2) | 1.0% | — | Argie Simple Inventory System | 2/6/2022 | 29/7/2026 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php. | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Emcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+4 | 23/5/2022 | 9/7/2026 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows… | |
| Modificada | Crítica (9.8) | 1.7% | — | Bdtask Multi Store Inventory Management System | 20/5/2022 | 17/6/2026 | Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.5% | — | Bdtask Multi Store Inventory Management System | 20/5/2022 | 17/6/2026 | Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pharmacy Sales AND Inventory System Project Pharmacy Sales AND Inventory System | 13/5/2022 | 17/6/2026 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=. | |
| Modificada | Media (6.5) | 0.30% | — | Hcltech Bigfix Inventory | 6/5/2022 | 17/6/2026 | This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application. | |
| Modificada | Media (6.5) | 0.36% | — | Hcltech Bigfix Inventory | 6/5/2022 | 17/6/2026 | There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (5) | 0.32% | — | Mini-inventory-and-sales-management-system Project Mini-inventory-and-sales-management-system | 4/3/2022 | 17/6/2026 | Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items. | |
| Modificada | Alta (7.5) | 1.7% | — | TraefikOracle Communications Unified Inventory Management | 17/2/2022 | 17/6/2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a… | |
| Modificada | Alta (7.8) | 0.25% | — | Snowsoftware Snow Inventory Java Scanner | 16/2/2022 | 17/6/2026 | A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… |