Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

599 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.0%—Ocsinventory-ng OCS Inventory NG6/5/201016/6/2026
Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php. NOTE:…
ModificadaAlta (7.5)1.2%—Ocsinventory-ng OCS Inventory NG28/4/201016/6/2026
Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.
ModificadaMedia (4.3)1.1%—Ocsinventory-ng OCS Inventory NG28/4/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)21%💥 ExploitJoomlamo COM Jinventory8/4/201016/6/2026
Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)0.99%💥 ExploitPhpwares PHP Inventory12/1/201016/6/2026
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a users details action, and allow remote attackers to execute arbitrary SQL commands via the (2) user (username) and (3) pass (password)…
ModificadaMedia (4.3)1.5%💥 ExploitPhpwares PHP Inventory12/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_id parameter in a suppliers details action.
ModificadaMedia (6)0.73%💥 ExploitPhpwares PHP Inventory12/1/201016/6/2026
SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (9)3.4%—HP Discovery&dependency Mapping Inventory17/11/200916/6/2026
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)3.0%💥 ExploitOcsinventory-ng OCS Inventory NG1/9/200916/6/2026
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.
ModificadaAlta (7.5)1.4%💥 ExploitOcsinventory-ng OCS Inventory NG1/9/200916/6/2026
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
ModificadaAlta (7.2)0.37%—Ocsinventory-ng OCS Inventory NGOcsinventory-ng Ocsinventory-agent9/7/200916/6/2026
Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
ModificadaMedia (5)3.2%💥 ExploitOcsinventory-ng OCS Inventory NG22/6/200916/6/2026
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
ModificadaMedia (4)1.8%—HP Discovery&dependency Mapping Inventory8/6/200916/6/2026
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.
ModificadaMedia (5)1.6%—Ocsinventory-ng OCS Inventory NG22/5/200916/6/2026
The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.
ModificadaAlta (10)4.0%💥 ExploitOcsinventory-ng OCS Inventory NG27/4/200916/6/2026
Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.
ModificadaMedia (6.8)60%💥 ExploitAnyinventory6/9/200716/6/2026
PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter.
ModificadaAlta (10)4.2%💥 ExploitPhpmyinventory19/6/200716/6/2026
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.
ModificadaAlta (7.8)1.9%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager27/4/200716/6/2026
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
ModificadaAlta (7.5)4.0%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager27/4/200716/6/2026
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
ModificadaAlta (7.5)1.1%💥 ExploitWebsite Designs FOR Less Inventory Manager17/11/200616/6/2026
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.
ModificadaMedia (6.8)1.4%—Website Designs FOR Less Inventory Manager17/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter.
ModificadaMedia (5)1.8%—IBM Inventory Scout27/9/200616/6/2026
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.
ModificadaMedia (6.8)1.3%—Accounting Receiving AND Inventory Administration Aria3/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter).
ModificadaBaja (2.1)0.34%—Bindview NetinventoryBindview Netrc31/12/200216/6/2026
BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI to HOSTCFG.INI and stores the passwords in cleartext until the audit is complete.
Orbitaley — Vulnerabilidades