Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.35% | — | Yeqifu Warehouse | 7/2/2026 | 17/6/2026 | A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\RoleController.java of the component Role-Permission Binding Handler. The manipulation results… | |
| Analizada | Media (5.5) | 0.45% | — | Feminer Warehouse Management System | 17/1/2026 | 17/6/2026 | A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknown functionality of the file /src/chkuser.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Baja (2.1) | 0.35% | — | Yeqifu Warehouse | 4/1/2026 | 17/6/2026 | A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component Request Handler. This manipulation causes improper authorization. The attack is… | |
| Analizada | Baja (2.1) | 0.53% | — | Yeqifu Warehouse | 2/1/2026 | 17/6/2026 | A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function createResponseEntity of the file warehouse\src\main\java\com\yeqifu\sys\common\AppFileUtils.java. The manipulation of the argument path results in path traversal. The attack… | |
| Aplazada | Baja (2) | 0.29% | — | Yangshare WarehousemanagerAI | 11/12/2025 | 17/6/2026 | A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCustomer of the file CustomerManageHandler.java. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Alta (8.1) | 0.79% | — | Yeqifu Warehouse Management System | 5/12/2025 | 25/9/2026 | Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authenticated attacker can… | |
| Analizada | Alta (7.5) | 0.70% | — | Yeqifu Warehouse Management System | 5/12/2025 | 25/9/2026 | The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system. This could lead to the leakage of… | |
| Aplazada | Alta (7.3) | 0.25% | — | Divvydrive Information Technologies INC Digital Corporate WarehouseAI | 12/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Digital Corporate Warehouse: before v.4.8.2.22. | |
| Aplazada | Media (6.1) | 0.24% | — | SAP Business WarehouseAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted. | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Business WarehouseAISAP Bw/4hanaAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality and availability of… | |
| Aplazada | Baja (2.7) | 0.43% | — | SAP Netweaver Business WarehouseAISAP CcawAI | 8/7/2025 | 17/6/2026 | SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the… | |
| Aplazada | Alta (7.7) | 0.41% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high… | |
| Aplazada | Alta (8.5) | 0.31% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 10/6/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data. | |
| Analizada | Media (6.9) | 0.54% | — | Yangshare Warehouse Management System | 26/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Analizada | Media (5.3) | 0.77% | — | Zzskzy Warehouse Refinement Management System | 12/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The manipulation of the argument showid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.77% | — | Zzskzy Warehouse Refinement Management System | 12/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The… | |
| Aplazada | Media (5.7) | 0.21% | — | SAP Business WarehouseAI | 11/3/2025 | 17/6/2026 | SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or… | |
| Analizada | Media (5.3) | 0.63% | — | Zzskzy Warehouse Refinement Management System | 9/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (5.1) | 0.32% | — | Yeqifu WarehouseAI | 12/1/2025 | 17/6/2026 | A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /resources/..;/inport/updateInport of the component Backend. The manipulation of the argument remark leads to cross site scripting. The attack can be launched… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Zeqp Wms-warehouse Management SystemAI | 2/12/2024 | 17/6/2026 | Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused. | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Business WarehouseAISAP BEX AnalyzerAI | 10/9/2024 | 17/6/2026 | Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application. | |
| Analizada | Alta (8.8) | 0.30% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. |