Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/locationmodify.php, in the description parameter. Exploitation of this vulnerability could allow a… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/unitofmeasurementmodify.php, in the description parameter. Exploitation of this vulnerability could… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancelist.php, in the delete parameter. Exploitation of this vulnerability could allow a… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuanceprint.php, in the issuanceno parameter. Exploitation of this vulnerability could allow… | |
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlist.php, in the deleted parameter. Exploitation of this vulnerability could allow a remote… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/statecreate.php, in the stateid parameter. Exploitation of this vulnerability could allow a remote… | |
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/countrycreate.php, in the countryid parameter. Exploitation of this vulnerability could allow a… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructurelist.php, in the description parameter. Exploitation of this vulnerability could allow a… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/countrylist.php, in the description parameter. Exploitation of this vulnerability could allow a… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructuredisplay.php, in the description parameter. Exploitation of this vulnerability could… | |
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grndisplay.php, in the grnno parameter. Exploitation of this vulnerability could allow a remote… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/unitofmeasurementcreate.php, in the unitofmeasurementid parameter. Exploitation of this… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/currencylist.php, in the description parameter. Exploitation of this vulnerability could allow a… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructurelinecreate.php, in the flatamount parameter. Exploitation of this vulnerability could… | |
| Modificada | Media (6.1) | 0.44% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancelinecreate.php, in the batchno parameter. Exploitation of this vulnerability could… | |
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlinecreate.php, in the batchno parameter. Exploitation of this vulnerability could allow a remote… | |
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/itemlist.php, in the description parameter. Exploitation of this vulnerability could allow a remote… | |
| Modificada | Media (6.1) | 0.40% | — | Ajaysharma Cups Easy | 25/1/2024 | 17/6/2026 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxcodemodify.php, in multiple parameters. Exploitation of this vulnerability could allow a remote… | |
| Modificada | Alta (7.5) | 0.63% | — | Botanikyazilim Pharmacy Automation | 22/11/2023 | 17/6/2026 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation allows Retrieve Embedded Sensitive Data. This issue affects Pharmacy Automation: before 2.1.133.0. | |
| Modificada | Media (4.8) | 0.45% | — | Armanidrisi DEV Blog | 21/11/2023 | 17/6/2026 | Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username. | |
| Modificada | Media (5.4) | 0.43% | — | Armanidrisi DEV Blog | 21/11/2023 | 17/6/2026 | Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim. | |
| Modificada | Alta (8.8) | 0.25% | — | Nareshparmar827 Post View Count | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naresh Parmar Post View Count plugin <= 1.8.2 versions. | |
| Modificada | Alta (7.5) | 0.57% | — | Farmacia Project Farmacia | 10/10/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in codeprojects Farmacia 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument usario/senha leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 1.2% | — | Fresenius-kabi Pharmahelp Firmware | 22/8/2023 | 17/6/2026 | An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information. | |
| Modificada | Media (6.8) | 1.8% | — | Samsung Harman Infotainment | 14/8/2023 | 17/6/2026 | Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object. |