Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.50% | — | Samsung Harman Infotainment | 14/8/2023 | 17/6/2026 | Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets. | |
| Modificada | Media (6.8) | 0.50% | — | Samsung Harman Infotainment | 14/8/2023 | 17/6/2026 | Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name. | |
| Modificada | Crítica (9.8) | 0.63% | — | Farmakom Remote Administration Console | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pharmacy Management System Project Pharmacy Management System | 6/8/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.25% | — | Nicearma Dnui-delete-not-used-image | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nicearma DNUI plugin <= 2.8.1 versions. | |
| Modificada | Crítica (9.8) | 0.85% | — | Pharmacy Management System Project Pharmacy Management System | 16/5/2023 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php. | |
| Modificada | Crítica (9.8) | 0.72% | — | Pharmacy Management System Project Pharmacy Management System | 19/2/2023 | 17/6/2026 | A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file add.php of the component Avatar Image Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 1.1% | — | Armandofiore Fl3r Feelbox | 13/2/2023 | 17/6/2026 | The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Analizada | Media (4.3) | 0.27% | — | Armandofiore Fl3r Feelbox | 30/1/2023 | 17/6/2026 | The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables | |
| Analizada | Media (6.1) | 0.29% | — | Armandofiore Fl3r Feelbox | 30/1/2023 | 17/6/2026 | The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Modificada | Alta (7.5) | 0.61% | — | Karmasis Infraskope Siem+ | 18/11/2022 | 17/6/2026 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed. | |
| Modificada | Alta (7.5) | 0.78% | — | Karmasis Infraskope Siem+ | 18/11/2022 | 17/6/2026 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information. | |
| Modificada | Media (5.3) | 0.53% | — | Karmasis Infraskope Siem+ | 16/11/2022 | 17/6/2026 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs. | |
| Modificada | Crítica (9.8) | 1.8% | — | Grunt-karma Project Grunt-karma | 14/10/2022 | 17/6/2026 | Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. | |
| Modificada | Crítica (9.8) | 0.93% | — | Phptpoint Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Phptpoint Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Phptpoint Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Phptpoint Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Pharmacy Management System Project Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Pharmacy Management System Project Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Pharmacy Management System Project Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Pharmacy Management System Project Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Pharmacy Management System Project Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Pharmacy Management System Project Pharmacy Management System | 2/8/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php. | |
| Modificada | Crítica (9.8) | 26% | 💥 PoC | Pharmacy Management System Project Pharmacy Management System | 20/5/2022 | 17/6/2026 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. |