Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.93% | — | Billing System Project Billing System | 22/11/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. | |
| Modificada | Alta (7.2) | 1.2% | — | Billing System Project Billing System | 18/10/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.2) | 0.78% | — | Billing System Project Billing System | 17/10/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. | |
| Modificada | Alta (7.2) | 0.86% | — | Billing System Project Project Billing System Project | 30/9/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | |
| Modificada | Alta (7.2) | 0.86% | — | Billing System Project Project Billing System Project | 30/9/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | |
| Modificada | Alta (7.2) | 1.7% | — | Billing System Project Project Billing System Project | 30/9/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. | |
| Modificada | Crítica (9.8) | 0.63% | — | Automated Beer Parlour Billing System Project Automated Beer Parlour Billing System | 12/8/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Modificada | Media (5.4) | 0.50% | — | Water Billing System Project Water Billing System | 24/5/2022 | 17/6/2026 | Water-billing-management-system v1.0 is affected by: Cross Site Scripting (XSS) via /wbms/classes/Users.php?f=save, firstname. | |
| Modificada | Crítica (9.8) | 1.1% | — | Water Billing System Project Water Billing System | 24/5/2022 | 17/6/2026 | Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id | |
| Modificada | Crítica (9.8) | 1.1% | — | Water Billing System Project Water Billing System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. | |
| Modificada | Media (4.3) | 0.43% | — | Totalonlinesolutions Advanced Webhost Billing System | 8/1/2021 | 17/6/2026 | Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page. | |
| Modificada | Crítica (9.8) | 2.6% | — | Water Billing System Project Water Billing System | 17/11/2020 | 17/6/2026 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php. | |
| Modificada | Baja (1.9) | 0.29% | — | Amberdms Billing System | 10/1/2014 | 16/6/2026 | Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job. | |
| Modificada | Media (6.4) | 1.1% | — | Amberdms Billing System | 10/1/2014 | 16/6/2026 | Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. | |
| Modificada | Alta (7.5) | 2.0% | — | Awbs Advanced Webhost Billing System | 20/1/2011 | 16/6/2026 | SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action. | |
| Modificada | Media (6.8) | 0.91% | — | Awbs Advanced Webhost Billing System | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Advanced Webhost Billing System | 31/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation." | |
| Modificada | Baja (3.5) | 0.92% | — | Advanced Webhost Billing System | 31/7/2007 | 16/6/2026 | Unspecified vulnerability in Advanced Webhost Billing System (AWBS) before 2.6.0 allows remote authenticated users to obtain configuration data about other dedicated servers via unspecified vectors. | |
| Modificada | Alta (7.5) | 6.0% | — | Advanced Webhost Billing System | 25/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Total Online Solutions Advanced Webhost Billing System | 1/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters. |