Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.22% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8) | 0.30% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Modificada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 0.31% | — | Siamonhasan Warehouse Inventory System | 20/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | |
| Analizada | Media (6.9) | 0.37% | — | Siamonhasan Warehouse Inventory System | 4/8/2024 | 17/6/2026 | A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change_password.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.37% | — | Siamonhasan Warehouse Inventory System | 4/8/2024 | 17/6/2026 | A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.4) | 0.24% | — | SAP Business WarehouseSAP Business Warehouse Virtual Comp | 9/7/2024 | 17/6/2026 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the… | |
| Analizada | Media (6.1) | 0.26% | — | SAP Business WarehouseSAP Business Warehouse Virtual Comp | 9/7/2024 | 17/6/2026 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and integrity of the application. | |
| Analizada | Alta (8.8) | 0.29% | — | IBM DB2IBM DB2 Warehouse | 29/5/2024 | 17/6/2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264. | |
| Analizada | Media (5.3) | 0.87% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed. | |
| Analizada | Alta (8.1) | 0.67% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components. | |
| Analizada | Media (5.5) | 0.23% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components. | |
| Analizada | Media (5.3) | 0.44% | — | Logint Lomag Warehouse Management | 1/5/2024 | 17/6/2026 | The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections. | |
| Analizada | Media (5.4) | 0.59% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Warehouse Management System 1.0. This vulnerability affects unknown code of the file pengguna.php. The manipulation of the argument admin_user/admin_nama/admin_alamat/admin_telepon leads to cross site scripting. The attack can be initiated remotely.… | |
| Analizada | Media (5.4) | 0.59% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Warehouse Management System 1.0. This affects an unknown part of the file customer.php. The manipulation of the argument nama_customer/alamat_customer/notelp_customer leads to cross site scripting. It is possible to initiate the attack… | |
| Analizada | Media (5.4) | 0.55% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file supplier.php. The manipulation of the argument nama_supplier/alamat_supplier/notelp_supplier leads to cross site scripting. The attack may be… | |
| Analizada | Media (5.4) | 0.55% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file barang.php. The manipulation of the argument nama_barang/merek leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (6.5) | 0.44% | — | SAP Business WarehouseSAP Bw/4hana | 11/7/2023 | 17/6/2026 | The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the… | |
| Modificada | Alta (8.8) | 0.51% | — | IBM DB2IBM DB2 Warehouse | 12/12/2022 | 17/6/2026 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210. | |
| Modificada | Crítica (9.8) | 0.84% | — | Warehouse Management System Project Warehouse Management System | 3/12/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.25% | — | IBM DB2 ON Cloud PAK FOR DataIBM DB2 Warehouse ON Cloud PAK FOR DataIBM Db2u | 1/12/2022 | 17/6/2026 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212. | |
| Modificada | Alta (7.5) | 0.95% | — | Oretnom23 Warehouse Management System | 26/7/2022 | 17/6/2026 | Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. |