Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.50%—Samsung Harman Infotainment14/8/202317/6/2026
Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.
ModificadaMedia (6.8)0.50%—Samsung Harman Infotainment14/8/202317/6/2026
Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.
ModificadaCrítica (9.8)0.63%—Farmakom Remote Administration Console8/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02.
ModificadaCrítica (9.8)1.0%—Pharmacy Management System Project Pharmacy Management System6/8/202317/6/2026
A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaAlta (8.8)0.25%—Nicearma Dnui-delete-not-used-image22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nicearma DNUI plugin <= 2.8.1 versions.
ModificadaCrítica (9.8)0.85%—Pharmacy Management System Project Pharmacy Management System16/5/202317/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.
ModificadaCrítica (9.8)0.72%—Pharmacy Management System Project Pharmacy Management System19/2/202317/6/2026
A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file add.php of the component Avatar Image Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…
AnalizadaCrítica (9.8)1.1%—Armandofiore Fl3r Feelbox13/2/202317/6/2026
The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
AnalizadaMedia (4.3)0.27%—Armandofiore Fl3r Feelbox30/1/202317/6/2026
The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables
AnalizadaMedia (6.1)0.29%—Armandofiore Fl3r Feelbox30/1/202317/6/2026
The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
ModificadaAlta (7.5)0.61%—Karmasis Infraskope Siem+18/11/202217/6/2026
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.
ModificadaAlta (7.5)0.78%—Karmasis Infraskope Siem+18/11/202217/6/2026
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information.
ModificadaMedia (5.3)0.53%—Karmasis Infraskope Siem+16/11/202217/6/2026
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.
ModificadaCrítica (9.8)1.8%—Grunt-karma Project Grunt-karma14/10/202217/6/2026
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
ModificadaCrítica (9.8)0.93%—Phptpoint Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.
ModificadaCrítica (9.8)0.93%—Phptpoint Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.
ModificadaCrítica (9.8)0.93%—Phptpoint Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.
ModificadaCrítica (9.8)0.93%—Phptpoint Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.
ModificadaCrítica (9.8)0.93%—Pharmacy Management System Project Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php.
ModificadaCrítica (9.8)0.93%—Pharmacy Management System Project Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.
ModificadaCrítica (9.8)0.93%—Pharmacy Management System Project Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php.
ModificadaCrítica (9.8)0.93%—Pharmacy Management System Project Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.
ModificadaCrítica (9.8)0.93%—Pharmacy Management System Project Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.
ModificadaCrítica (9.8)0.93%—Pharmacy Management System Project Pharmacy Management System2/8/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.
ModificadaCrítica (9.8)26%💥 PoCPharmacy Management System Project Pharmacy Management System20/5/202217/6/2026
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
Orbitaley — Vulnerabilidades