Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.41% | — | Janobe Water Billing System | 30/8/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. | |
| Analizada | Media (5.5) | 0.41% | — | Janobe Water Billing System | 30/8/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited. | |
| Analizada | Media (5.5) | 0.41% | — | Oretnom23 Simple Cafe Billing System | 30/8/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /sales_report.php. The manipulation of the argument month leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.41% | — | Oretnom23 Simple Cafe Billing System | 30/8/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Simple Cafe Billing System 1.0. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.55% | — | Campcodes Online Water Billing System | 26/8/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the file /addclient1.php. Executing manipulation of the argument lname can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Other… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Water Billing System | 25/8/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file /editecex.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.42% | 💥 PoC | Campcodes Online Water Billing System | 13/8/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing of the file /viewbill.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (8) | 0.41% | 💥 PoC | Magnussolution Magnusbilling | 31/7/2025 | 17/6/2026 | A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval. | |
| Analizada | Media (5.5) | 0.45% | — | Anisha Electricity Billing System | 14/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/change_password.php. The manipulation of the argument new_password leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Kashipara Billing SoftwareAI | 13/5/2025 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Analizada | Media (4.8) | 0.37% | — | Fabian School Billing System | 29/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public… | |
| Analizada | Media (6) | 0.42% | — | Oracle Financial Services Revenue Management AND Billing | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 5.1.0.0.0, 6.1.0.0.0 and 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Silverplugins217 Multiple Shipping AND Billing Address FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows Object Injection.This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.29% | — | Zoho BillingAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing – Embed Payment Form allows Stored XSS. This issue affects Zoho Billing – Embed Payment Form: from n/a through 4.0. | |
| Modificada | Media (5.4) | 0.94% | 💥 Exploit | Magnussolution Magnusbilling | 21/3/2025 | 28/8/2026 | Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Magnussolution Magnusbilling | 21/3/2025 | 28/8/2026 | Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Silverplugins217 Multiple Shipping AND Billing Address FOR WoocommerceAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For… | |
| Analizada | Media (4.8) | 0.35% | — | Razormist Telecom Billing Management System | 23/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argument name/phonenumber leads to buffer overflow. Local access is required to… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Silverplugins217 Different-shipping-and-billing-address-for-woocommerceAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For… | |
| Analizada | Media (5.3) | 0.81% | — | Razormist Telecom Billing Management System | 22/9/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of the argument uname leads to buffer overflow. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.70% | — | Oretnom23 Electric Billing Management System | 30/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.62% | — | Oretnom23 Electric Billing Management System | 30/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Electric Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?page=tracks of the component Connection Code Handler. The manipulation of the argument code leads to sql injection. The attack may be… | |
| Analizada | Media (6.9) | 0.58% | — | Angeljudesuarez Billing System | 18/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. The manipulation of the argument lname/fname/mi/address/contact/meterReader leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.62% | — | Angeljudesuarez Billing System | 15/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.58% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view_bill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… |