Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3090▲ 500 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
5682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Campcodes Grocery Sales AND Inventory System | 16/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_receiving. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Analizada | Media (5.5) | 0.47% | — | Campcodes Grocery Sales AND Inventory System | 16/9/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_category. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.43% | — | Campcodes Grocery Sales AND Inventory System | 16/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Grocery Sales AND Inventory System | 16/9/2025 | 30/9/2026 | Se encontró una vulnerabilidad en Campcodes Grocery Sales and Inventory System 1.0. Afecta a una función desconocida del archivo /ajax.PHP?action=delete_category. La manipulación del argumento ID resulta en inyección SQL. El ataque puede ser llevado a cabo de forma remota. El exploit ha sido hecho público y podría ser… | |
| Analizada | Baja (2.1) | 0.37% | — | Bytecodealliance Webassembly Micro Runtime | 16/9/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first operand (memory address pointer) is greater… | |
| Modificada | Media (5.5) | 0.34% | — | Apple Xcode | 15/9/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. | |
| Modificada | Alta (8.2) | 0.20% | — | Apple Xcode | 15/9/2025 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. | |
| Modificada | Alta (7.1) | 0.21% | — | Apple Xcode | 15/9/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox. | |
| Modificada | Media (4) | 0.34% | — | Apple Xcode | 15/9/2025 | 1/10/2026 | Se abordó un problema de manejo de rutas con validación mejorada. Este problema está corregido en Xcode 26. Procesar un valor de ruta excesivamente grande puede provocar el cierre inesperado de un proceso. | |
| Analizada | Media (5.5) | 0.53% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php?q=result&searchfor=bycompany. This manipulation of the argument Search causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.46% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform.php. The manipulation of the argument picture results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Computer Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_searchfrm.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Computer Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/us_transac.php?action=add. Executing manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to… | |
| Analizada | Media (5.5) | 0.50% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Online Job Finder System 1.0. This issue affects some unknown processing of the file /advancesearch.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.43% | — | Campcodes Computer Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/sup_searchfrm.php?action=edit. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Computer Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Laundry Management System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Laundry Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Grocery Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=delete_product. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Grocery Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_supplier. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be… | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Grocery Sales AND Inventory System | 14/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_supplier. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Grocery Sales AND Inventory System | 14/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_customer. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public… | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Grocery Sales AND Inventory System | 14/9/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_customer. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Itsourcecode Baptism Information Management System | 14/9/2025 | 30/9/2026 | Se determinó una vulnerabilidad en itsourcecode Baptism Information Management System 1.0. Afectada es una función desconocida del archivo /listbaptism.PHP. Esta manipulación del argumento bapt_id causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser… | |
| Analizada | Baja (2.1) | 0.42% | — | Codesiddhant Jasmin Ransomware | 14/9/2025 | 30/9/2026 | Se determinó una vulnerabilidad en codesiddhant Jasmin Ransomware hasta 1.0.1. Esta vulnerabilidad afecta código desconocido del archivo /handshake.php. Esta manipulación del argumento machine_name/computer_user/os/date/time/ip/location/systemid/password causa inyección SQL. El ataque puede iniciarse remotamente. El… |