Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

614 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.24%—10-strike Network Inventory Explorer15/1/202617/6/2026
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation and execute code…
AplazadaAlta (8.5)0.16%—Ocsinventory-ng OCS Inventory NGAI19/12/202517/6/2026
OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.
AplazadaMedia (6.4)0.32%—Teclib Database Inventory PluginAI19/12/202517/6/2026
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability or misconfiguration), user-controlled…
AnalizadaMedia (5.3)0.35%—Inventory Management System Project Inventory Management System15/12/202517/6/2026
Inventory Management System 1 was discovered to contain a SQL injection vulnerability.
AnalizadaMedia (6.1)0.22%—Inventory Management System Project Inventory Management System15/12/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
AplazadaAlta (8.7)0.20%—Redhat Runtimes-inventory-rhel8-operatorAI15/12/202522/8/2026
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user…
AnalizadaBaja (2)0.35%—Warren-daloyan Inventory Management System8/12/202517/6/2026
A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
AnalizadaMedia (5.5)0.47%—Warren-daloyan Inventory Management System23/11/202517/6/2026
A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The exploit has been made available to the public…
AplazadaMedia (4.3)0.29%—Teclib Database Inventory PluginAI18/11/202517/6/2026
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. This issue has been patched in version 1.0.3.
ModificadaMedia (5.5)0.38%—Codeastro Simple Inventory System17/11/202517/6/2026
A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed…
AnalizadaMedia (5.5)0.39%—Janobe Inventory Management System17/11/202517/6/2026
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.38%—Janobe Inventory Management System16/11/202517/6/2026
A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
AnalizadaBaja (2.1)0.32%—Janobe Inventory Management System16/11/202517/6/2026
A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.39%—Janobe Inventory Management System16/11/202517/6/2026
A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be…
AnalizadaBaja (2.1)0.32%—Janobe Inventory Management System16/11/202517/6/2026
A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be…
AnalizadaMedia (5.5)0.39%—Janobe Inventory Management System16/11/202517/6/2026
A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be…
AnalizadaBaja (2)0.35%—Janobe Inventory Management System15/11/202517/6/2026
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the argument PROMODEL leads to sql injection. The attack may be performed from remote. The exploit has been disclosed…
AplazadaMedia (4.4)0.19%—Squirrels Auto InventoryAI11/11/202517/6/2026
The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AplazadaAlta (7.2)0.51%—Dmitry V Barcode Scanner Lite POS TO Manage Products Inventory AND OrdersAI6/11/202517/6/2026
Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.10.4.
AplazadaAlta (7.5)7.0%—Glpi Inventory PluginAI4/11/202517/6/2026
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. This issue is fixed in version 1.5.1.
AnalizadaMedia (5.3)0.22%—Phoenix616 Inventorygui27/10/202517/6/2026
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the…
AnalizadaMedia (4.3)0.25%—Phoenix616 Inventorygui27/10/202517/6/2026
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.1-SNAPSHOT and earlier contain a vulnerability where any plugin using the `GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version…
AnalizadaMedia (5.9)0.26%—Phoenix616 Inventorygui27/10/202517/6/2026
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version…
AnalizadaBaja (2.1)0.34%—Codeastro Simple Inventory System11/10/202517/6/2026
A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of the argument editBrandName results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be…
AnalizadaBaja (2.1)0.34%—Codeastro Simple Inventory System11/10/20251/10/2026
A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Orbitaley — Vulnerabilidades