Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.49% | — | Senior-walter Web-based Pharmacy Product Management System | 27/3/2026 | 17/6/2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry, allowing negative values to be processed. This causes the system to decrease the inventory level instead of increasing… | |
| Analizada | Alta (7.5) | 0.38% | — | Senior-walter Web-based Pharmacy Product Management System | 27/3/2026 | 17/6/2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly… | |
| Analizada | Media (6.9) | 0.19% | — | Raimersoft Rarmaradio | 22/3/2026 | 17/6/2026 | RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a malicious payload exceeding 4000 bytes into the Server field via the Settings menu to trigger an… | |
| Analizada | Media (6.9) | 0.18% | — | Raimersoft Rarmaradio | 22/3/2026 | 17/6/2026 | RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash. | |
| Aplazada | Media (5.3) | 0.38% | — | Sourcecodester Web-based Pharmacy Product Management SystemAI | 12/3/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown function of the file add_admin.php. Such manipulation leads to improper authorization. The attack may be launched remotely. | |
| Analizada | Baja (2) | 0.35% | — | Senior-walter Web-based Pharmacy Product Management System | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploit has been released… | |
| Analizada | Baja (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 17/6/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php. | |
| Analizada | Baja (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 17/6/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php. | |
| Analizada | Baja (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 17/6/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php. | |
| Analizada | Baja (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 17/6/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 2/3/2026 | 17/6/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 2/3/2026 | 17/6/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 2/3/2026 | 17/6/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 2/3/2026 | 17/6/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 2/3/2026 | 17/6/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | |
| Analizada | Baja (1.3) | 0.51% | — | Senior-walter Web-based Pharmacy Product Management System | 2/3/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitability is difficult.… | |
| Aplazada | Alta (7.1) | 0.24% | — | Harman79 ID ArraysAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harman79 ID Arrays id-arrays allows DOM-Based XSS.This issue affects ID Arrays: from n/a through <= 2.1.2. | |
| Aplazada | Alta (8.7) | 0.48% | — | Sarman Soft Software AND Technology Services Industry AND Trade CMSAI | 10/2/2026 | 17/6/2026 | Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond… | |
| Aplazada | Media (4.6) | 0.41% | — | Raimersoft RarmaradioAI | 16/1/2026 | 17/6/2026 | RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger application instability… | |
| Aplazada | Alta (8.7) | 0.53% | — | Dawa-pharmaAI | 4/12/2025 | 17/6/2026 | dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access. | |
| Analizada | Media (6.1) | 0.22% | — | Senior-walter Web-based Pharmacy Product Management System | 2/12/2025 | 17/6/2026 | Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field. | |
| Modificada | Alta (8.8) | 0.21% | — | Senior-walter Web-based Pharmacy Product Management System | 10/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection. | |
| Analizada | Baja (2.1) | 0.48% | — | Bdtask Pharmacare | 27/10/2025 | 17/6/2026 | A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now public and may be… | |
| Aplazada | Alta (8.7) | 0.49% | — | Karmada DashboardAI | 24/10/2025 | 17/6/2026 | Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce… | |
| Analizada | Media (6.1) | 0.23% | — | Senior-walter Web-based Pharmacy Product Management System | 30/9/2025 | 17/6/2026 | SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field. |