Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.34% | — | Codeastro Simple Pharmacy Management System | 22/9/2025 | 17/6/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file /view.php. This manipulation of the argument bar_code causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Crítica (9.8) | 0.44% | — | ArmalifeAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arma Store Armalife allows SQL Injection. This issue affects Armalife: through 20250916. NOTE: The vendor did not inform about the completion of… | |
| Modificada | Alta (8.1) | 0.43% | — | Senior-walter Web-based Pharmacy Product Management System | 15/9/2025 | 5/7/2026 | SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users. | |
| Analizada | Baja (1.9) | 0.29% | — | Code-projects POS Pharmacy System | 3/9/2025 | 17/6/2026 | A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /main/products.php. This manipulation of the argument product_code/gen_name/product_name/supplier causes cross site scripting. The attack can be initiated remotely. The exploit has been made available… | |
| Aplazada | Alta (7.1) | 0.24% | — | Vikas Sharma Iframe BlockAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Sharma iFrame Block allows Stored XSS. This issue affects iFrame Block: from n/a through 0.1.1. | |
| Aplazada | Media (5.1) | 0.40% | — | Pharmacy POS PHP ScriptAI | 16/7/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the u_medicine_name parameter in /edit_medicine.php. This vulnerability can be exploited to steal sensitive… | |
| Analizada | Baja (2.1) | 0.42% | — | Krishna9772 Pharmacy Management System | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file quantity_upd.php. The manipulation of the argument med_name/med_cat/ex_date leads to sql injection. It is possible to launch… | |
| Analizada | Alta (8.6) | 0.49% | — | Senior-walter Web-based Pharmacy Product Management System | 28/5/2025 | 17/6/2026 | Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg. | |
| Aplazada | Alta (7.1) | 0.28% | — | Saurabh Sharma WP Post Modules FOR ElementorAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SaurabhSharma WP Post Modules for Elementor wp-post-modules-el allows Reflected XSS.This issue affects WP Post Modules for Elementor: from n/a through <= 2.5.0. | |
| Analizada | Media (6.5) | 0.28% | — | Samsung Harman Mgu21 Firmware | 22/5/2025 | 17/6/2026 | Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Harman Becker MGU21 devices. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (4.8) | 0.35% | — | Code-projects Pharmacy Management System | 18/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. This affects the function medicineType::take_order of the component Add Order Details. The manipulation leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Codeastro Pharmacy Management System | 16/5/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (4.8) | 0.36% | — | Senior-walter Web-based Pharmacy Product Management System | 11/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Add User Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.29% | — | Senior-walter Web-based Pharmacy Product Management System | 5/5/2025 | 17/6/2026 | SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field. | |
| Aplazada | Media (4.9) | 0.21% | — | Ankur Vishwakarma WP Avcl Automation HelperAI | 24/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4. | |
| Analizada | Media (4.8) | 0.40% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress leads to cross site scripting. It is possible to initiate the… | |
| Analizada | Media (4.8) | 0.40% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument txtcategory_name leads to cross site scripting. The attack may be… | |
| Analizada | Media (4.8) | 0.40% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-product.php. The manipulation of the argument txtprice/txtproduct_name leads to cross site scripting. The attack can be… | |
| Analizada | Media (4.8) | 0.41% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproductID/txtprice/txtexpirydate leads to cross site scripting. It is possible to… | |
| Analizada | Media (4.8) | 0.45% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtconfirm_password/txtnew_password/txtold_password leads to cross site scripting.… | |
| Analizada | Media (4.8) | 0.38% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassword/txtfullname/txtemail leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.97% | — | Senior-walter Web-based Pharmacy Product Management System | 18/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-product.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be launched remotely. The… | |
| Analizada | Media (5.3) | 0.55% | — | Senior-walter Web-based Pharmacy Product Management System | 17/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.55% | — | Senior-walter Web-based Pharmacy Product Management System | 17/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /edit-product.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.29% | — | Kush Sharma Kush Micro NewsAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kush Sharma Kush Micro News kush-micro-news allows Stored XSS.This issue affects Kush Micro News: from n/a through <= 1.6.7. |