Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
599 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.0% | — | Ocsinventory-ng OCS Inventory NG | 6/5/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php. NOTE:… | |
| Modificada | Alta (7.5) | 1.2% | — | Ocsinventory-ng OCS Inventory NG | 28/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Ocsinventory-ng OCS Inventory NG | 28/4/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Joomlamo COM Jinventory | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Phpwares PHP Inventory | 12/1/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a users details action, and allow remote attackers to execute arbitrary SQL commands via the (2) user (username) and (3) pass (password)… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpwares PHP Inventory | 12/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_id parameter in a suppliers details action. | |
| Modificada | Media (6) | 0.73% | 💥 Exploit | Phpwares PHP Inventory | 12/1/2010 | 16/6/2026 | SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (9) | 3.4% | — | HP Discovery&dependency Mapping Inventory | 17/11/2009 | 16/6/2026 | Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Ocsinventory-ng OCS Inventory NG | 1/9/2009 | 16/6/2026 | SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Ocsinventory-ng OCS Inventory NG | 1/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php. | |
| Modificada | Alta (7.2) | 0.37% | — | Ocsinventory-ng OCS Inventory NGOcsinventory-ng Ocsinventory-agent | 9/7/2009 | 16/6/2026 | Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Ocsinventory-ng OCS Inventory NG | 22/6/2009 | 16/6/2026 | Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter. | |
| Modificada | Media (4) | 1.8% | — | HP Discovery&dependency Mapping Inventory | 8/6/2009 | 16/6/2026 | Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | Ocsinventory-ng OCS Inventory NG | 22/5/2009 | 16/6/2026 | The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Alta (10) | 4.0% | 💥 Exploit | Ocsinventory-ng OCS Inventory NG | 27/4/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 60% | 💥 Exploit | Anyinventory | 6/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter. | |
| Modificada | Alta (10) | 4.2% | 💥 Exploit | Phpmyinventory | 19/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter. | |
| Modificada | Alta (7.8) | 1.9% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 27/4/2007 | 16/6/2026 | The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field. | |
| Modificada | Alta (7.5) | 4.0% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 27/4/2007 | 16/6/2026 | Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Website Designs FOR Less Inventory Manager | 17/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Website Designs FOR Less Inventory Manager | 17/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter. | |
| Modificada | Media (5) | 1.8% | — | IBM Inventory Scout | 27/9/2006 | 16/6/2026 | Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Accounting Receiving AND Inventory Administration Aria | 3/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter). | |
| Modificada | Baja (2.1) | 0.34% | — | Bindview NetinventoryBindview Netrc | 31/12/2002 | 16/6/2026 | BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI to HOSTCFG.INI and stores the passwords in cleartext until the audit is complete. |