Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.62% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_billing.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.3) | 0.62% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Establishment Billing Management System 1.0. Affected is an unknown function of the file /manage_block.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Establishment Billing Management System 1.0. This affects an unknown part of the file /manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.58% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /manage_payment.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_block. The manipulation of the argument id leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.65% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated… | |
| Analizada | Media (5.3) | 0.45% | — | Oretnom23 Establishment Billing Management System | 31/7/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated… | |
| Modificada | Media (6.1) | 0.26% | — | Oracle Financial Services Revenue Management AND Billing | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 6.0.0.0.0 and 6.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analizada | Alta (8.1) | 0.54% | — | Angeljudesuarez Billing System | 9/7/2024 | 17/6/2026 | SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Crítica (9.8) | 0.73% | — | Itsourcecode Billing System | 13/6/2024 | 17/6/2026 | A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter. | |
| Modificada | Crítica (9.8) | 0.64% | — | Kashipara Billing Software | 13/1/2024 | 17/6/2026 | A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.57% | — | Kashipara Billing Software | 13/1/2024 | 17/6/2026 | A vulnerability has been found in Kashipara Billing Software 1.0 and classified as critical. This vulnerability affects unknown code of the file party_submit.php of the component HTTP POST Request Handler. The manipulation of the argument party_name leads to sql injection. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.53% | — | Kashipara Billing Software | 13/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bill.php of the component HTTP POST Request Handler. The manipulation of the argument itemtypeid leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.53% | — | Kashipara Billing Software | 13/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_delivery_list.php of the component HTTP POST Request Handler. The manipulation of the argument customer_details leads to sql injection. The attack… | |
| Modificada | Crítica (9.8) | 0.53% | — | Kashipara Billing Software | 13/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the file buyer_detail_submit.php of the component HTTP POST Request Handler. The manipulation of the argument gstn_no leads to sql injection. The attack can be launched… | |
| Analizada | Crítica (9.8) | 0.75% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Billing Software | 4/1/2024 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.65% | — | Fabian Water Billing System | 25/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Water Billing System 1.0. This affects an unknown part of the file /addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… |