Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.5)0.11%—Armatura ONEAI2/10/20263/10/2026
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
RecibidaAlta (8.6)0.13%—Armatura ONEAI2/10/20263/10/2026
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database…
RecibidaAlta (8.6)0.09%—Armatura ONEAI2/10/20263/10/2026
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a…
AplazadaBaja (2.1)0.20%—Codeastro Simple Pharmacy Management SystemAI2/10/20262/10/2026
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might…
AplazadaBaja (2.1)0.20%—Codeastro Simple Pharmacy Management SystemAI2/10/20262/10/2026
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may…
AplazadaAlta (7.2)0.21%—BarmanAI29/9/202630/9/2026
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and…
AplazadaMedia (4.3)0.28%—Arma Digital Media INC Website TemplateAI11/9/202611/9/2026
Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaMedia (5.5)0.50%—Itsourcecode Online Pharmacy SystemAI24/8/202624/8/2026
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been…
AplazadaAlta (7.5)0.51%—Saurabhsharma Newsplus ShortcodesAIPHPAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.
AplazadaMedia (4.8)0.19%—Pragdave EarmarkAI17/6/202622/6/2026
Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site scripting via unescaped HTML attribute values. 'Elixir.Earmark.Transform':_make_att1/2 in lib/earmark/transform.ex splices attribute values verbatim between two literal " bytes: [" ", name, "=\"",…
AplazadaMedia (6.9)0.78%—Dharma BookingAI15/6/202617/6/2026
WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway parameter in…
AnalizadaMedia (5.8)0.12%—Spearman Unbounded-spsc12/6/202617/6/2026
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly available patches.
AplazadaMedia (5.5)0.31%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been…
AplazadaBaja (2)0.25%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation…
AplazadaBaja (2)0.20%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The…
AplazadaBaja (2)0.20%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated…
AplazadaBaja (2)0.20%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit…
AplazadaBaja (2)0.20%—Sourcecodestar Pharmacy Sales AND Inventory SystemAI1/6/202622/7/2026
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be…
AplazadaCrítica (9.1)0.65%—Lalanachami Pharmacy Management SystemAI19/5/202624/7/2026
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via…
AplazadaCrítica (9.8)0.63%—Lalanachami Pharmacy Management SystemAI19/5/202624/7/2026
The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body
AplazadaBaja (1.9)0.35%—Sourcecodester Pharmacy Sales AND Inventory SystemAI8/5/202617/6/2026
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI7/5/202617/6/2026
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.32%—Sourcecodester Web-based Pharmacy Product Management SystemAI4/5/202617/6/2026
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and…
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/5/202617/6/2026
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=save_customer. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AplazadaMedia (5.5)0.41%—Sourcecodester Pharmacy Sales AND Inventory SystemAI1/5/202617/6/2026
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_customer. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.