Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

599 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.37%—Ahsanriaz26gmailcom Sales AND Inventory System23/3/202617/6/2026
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /view_product.php of the component HTTP POST Request Handler. Executing a manipulation of the argument searchtxt can lead to sql injection. The attack may be performed from…
AnalizadaBaja (2.1)0.37%—Ahsanriaz26gmailcom Sales AND Inventory System23/3/202617/6/2026
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection. The attack is…
AnalizadaBaja (2.1)0.47%—Ahsanriaz26gmailcom Sales AND Inventory System23/3/202617/6/2026
A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection. The attack can be executed remotely. The exploit is publicly…
AnalizadaBaja (2.1)0.37%—Ahsanriaz26gmailcom Sales AND Inventory System23/3/202617/6/2026
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection. Remote exploitation of the attack is possible. The exploit has…
ModificadaBaja (2.1)0.35%—Ahsanriaz26gmailcom Sales AND Inventory System23/3/202617/6/2026
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the component HTTP GET Request Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public…
AplazadaBaja (2.1)0.32%—Mindinventory MindsqlAI20/3/202617/6/2026
A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the file mindsql/core/mindsql_core.py. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was…
AplazadaBaja (2.1)0.39%—Mindinventory MindsqlAI20/3/202617/6/2026
A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing a manipulation results in code injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about…
AnalizadaAlta (8.8)0.38%—Glpi-project Glpi Inventory18/3/202617/6/2026
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System9/3/202617/6/2026
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.php of the component GET Parameter Handler. This manipulation of the argument sellid causes sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System9/3/202617/6/2026
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the component GET Parameter Handler. The manipulation of the argument purchaseid results in sql injection. The attack may be performed from remote. The exploit has been made…
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System9/3/202617/6/2026
A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulation of the argument searchtxt leads to sql injection. The attack is possible to be carried out remotely. The exploit has…
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System9/3/202617/6/2026
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_supplier_details.php of the component POST Parameter Handler. Executing a manipulation of the argument stock_name1 can lead to sql injection. The attack can be executed…
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System8/3/202617/6/2026
A vulnerability was identified in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function of the file /check_item_details.php. The manipulation of the argument stock_name1 leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System8/3/202617/6/2026
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /check_customer_details.php of the component POST Handler. Executing a manipulation of the argument stock_name1 can lead to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System8/3/202617/6/2026
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /add_stock.php. Performing a manipulation of the argument cost results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
AnalizadaBaja (2.1)0.49%—Ahsanriaz26gmailcom Sales AND Inventory System8/3/202617/6/2026
A vulnerability has been found in SourceCodester Sales and Inventory System up to 1.0. The impacted element is an unknown function of the file /add_sales_print.php. Such manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaAlta (8.8)0.24%—Symantec InventoryAI6/3/202617/6/2026
Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensitive database…
AnalizadaMedia (6.1)0.28%—Glpi-project Glpi Inventory3/3/202617/6/2026
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.
AnalizadaMedia (5.3)0.53%—Go2ismail Asp.net-core-inventory-order-management-system26/2/202617/6/2026
A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is…
AnalizadaBaja (2.1)0.71%—Go2ismail Asp.net-core-inventory-order-management-system26/2/202617/6/2026
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public…
AplazadaAlta (8.4)0.38%—10-strike Network Inventory ExplorerAI5/2/202617/6/2026
10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code…
AplazadaAlta (8.4)0.71%—10-strike Network Inventory ExplorerAI5/2/202617/6/2026
10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution…
AplazadaMedia (5.1)0.33%—Online Inventory ManagerAI3/2/202617/6/2026
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side…
AplazadaAlta (8.4)0.54%—10-strike Network Inventory ExplorerAI28/1/202617/6/2026
10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code execution.
AnalizadaAlta (8.4)0.71%—10-strike Network Inventory Explorer15/1/202617/6/2026
10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the target system.