Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.70% | — | Janobe Point OF Sales AND Inventory Management System | 20/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Modificada | Media (5.3) | 0.45% | — | Oretnom23 Simple Inventory Management System | 17/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php of the component Order Handler. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely.… | |
| Analizada | Media (5.4) | 0.55% | — | Bdtask Multi Store Inventory Management System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Store Update Page. The manipulation of the argument Store Name/Store Address leads to cross site scripting. The attack may… | |
| Analizada | Media (5.4) | 1.2% | 💥 PoC | Bdtask Multi Store Inventory Management System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Name/Unit Name leads to cross site scripting. The attack can be… | |
| Analizada | Media (4.8) | 0.52% | — | Bdtask Multi Store Inventory Management System | 27/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been classified as problematic. Affected is an unknown function of the component Page Title Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (4.3) | 0.55% | — | Bdtask Wholesale Inventory Management SystemAI | 19/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask Wholesale Inventory Management System up to 20240311. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 0.63% | — | Mayurik Free AND Open Source Inventory Management System | 27/2/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated… | |
| Modificada | Media (6.5) | 0.35% | — | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 30/1/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component. | |
| Modificada | Media (5.4) | 0.50% | — | Codeastro POS AND Inventory Management System | 11/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /new_item of the component New Item Creation Page. The manipulation of the argument new_item leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 0.66% | — | Mayurik Free AND Open Source Inventory Management System | 29/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /app/ajax/sell_return_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack may be initiated… | |
| Modificada | Alta (8.8) | 0.63% | — | Mayurik Free AND Open Source Inventory Management System | 29/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Free and Open Source Inventory Management System 1.0. This affects an unknown part of the file /ample/app/action/edit_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Media (6.1) | 0.53% | — | Code-projects Point OF Sales AND Inventory Management System | 22/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (6.1) | 0.58% | — | Codeastro POS AND Inventory Management System | 13/12/2023 | 17/6/2026 | A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /item/item_con. The manipulation of the argument item_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.68% | — | Codeastro POS AND Inventory Management System | 13/12/2023 | 17/6/2026 | A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /accounts_con/register_account. The manipulation of the argument Username with the input <script>alert(document.cookie)</script> leads to cross… | |
| Modificada | Alta (8.8) | 0.74% | — | Codeastro POS AND Inventory Management System | 13/12/2023 | 17/6/2026 | A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of the argument account_type with the input… | |
| Modificada | Crítica (9.8) | 0.80% | — | Mayurik Free AND Open Source Inventory Management System | 27/11/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Free and Open Source Inventory Management System 1.0. Affected is an unknown function of the file /ample/app/ajax/member_data.php. The manipulation of the argument columns leads to sql injection. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.80% | — | Mayurik Free AND Open Source Inventory Management System | 27/11/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliar_data.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated… | |
| Modificada | Alta (7.8) | 0.30% | — | Code-projects Inventory Management | 14/11/2023 | 17/6/2026 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component. | |
| Modificada | Media (5.5) | 0.31% | — | Code-projects Inventory Management | 14/11/2023 | 17/6/2026 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component. | |
| Modificada | Media (5.4) | 0.51% | — | Code-projects Inventory Management | 14/11/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component. | |
| Modificada | Media (5.4) | 0.43% | 💥 PoC | Mayurik Inventory Management System | 26/10/2023 | 17/6/2026 | Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function. | |
| Modificada | Alta (8.8) | 0.76% | 💥 PoC | Mayurik Inventory Management System | 26/10/2023 | 17/6/2026 | Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function. | |
| Modificada | Media (6.1) | 0.69% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 8/9/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section. | |
| Modificada | Media (6.1) | 0.64% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 7/9/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section. | |
| Modificada | Crítica (9.8) | 0.99% | — | Mayurik Inventory Management System | 4/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the… |