Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Campcodes Grocery Sales AND Inventory System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_supplier. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be… | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Grocery Sales AND Inventory System | 14/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_supplier. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Grocery Sales AND Inventory System | 14/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_customer. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public… | |
| Analizada | Media (5.5) | 0.41% | — | Campcodes Grocery Sales AND Inventory System | 14/9/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_customer. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (2.1) | 0.42% | — | Campcodes Grocery Sales AND Inventory System | 6/9/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /index.php. The manipulation of the argument page results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Grocery Sales AND Inventory System | 6/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Grocery Sales AND Inventory System | 6/9/2025 | 17/6/2026 | A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_receiving. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Alta (7.1) | 0.13% | — | Nick Ciske TO Lead FOR SalesforceAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce salesforce-wordpress-to-lead allows Reflected XSS.This issue affects To Lead For Salesforce: from n/a through <= 2.7.3.9. | |
| Analizada | Baja (2.1) | 0.41% | — | Campcodes Sales AND Inventory System | 3/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the argument page can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.41% | — | Campcodes Sales AND Inventory System | 3/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Such manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Computer Sales AND Inventory System | 1/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/pos_transac.php?action=add. Executing manipulation of the argument cash/firstname can lead to sql injection. The attack may be performed from remote. The exploit has been published… | |
| Aplazada | Alta (7.5) | 0.57% | — | Saleswonder Team CF7 WOW StylerAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler allows PHP Local File Inclusion.This issue affects CF7 WOW Styler: from n/a through <= 1.7.2. | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.51% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (2.1) | 0.41% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation of the argument select2112 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.41% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was identified in 1000 Projects Sales Management System 1.0. This issue affects some unknown processing of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.51% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Baja (3.7) | 0.23% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g. attachments). An unauthenticated attacker… | |
| Analizada | Alta (8.6) | 0.21% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply… | |
| Analizada | Media (5.1) | 0.21% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include some arbitrary… | |
| Analizada | Alta (8.8) | 0.42% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity,… | |
| Analizada | Media (5.3) | 0.29% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given… | |
| Analizada | Alta (8.8) | 0.38% | — | Salesagility Suitecrm | 7/8/2025 | 17/6/2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Saleswonder WebinarignitionAI | 24/7/2025 | 17/6/2026 | The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_register_support` functions… | |
| Analizada | Media (5.5) | 0.62% | — | Campcodes Sales AND Inventory System | 21/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/settings_update.php of the component Setting Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit… |