Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.36% | — | Auto Dealer Management System Project Auto Dealer Management System | 14/4/2023 | 9/7/2026 | Auto Dealer Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the name parameter at /classes/SystemSettings.php?f=update_settings. | |
| Modificada | Crítica (9.8) | 0.62% | — | Auto Dealer Management System Project Auto Dealer Management System | 13/4/2023 | 9/7/2026 | Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Alta (8.8) | 3.1% | — | Auto Dealer Management System Project Auto Dealer Management System | 19/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 1.7% | — | Auto Dealer Management System Project Auto Dealer Management System | 19/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is an unknown function of the file /adms/admin/?page=user/manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 1.6% | — | Auto Dealer Management System Project Auto Dealer Management System | 18/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. This vulnerability affects unknown code of the file /adms/admin/?page=vehicles/sell_vehicle. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 1.6% | — | Auto Dealer Management System Project Auto Dealer Management System | 18/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /adms/admin/?page=vehicles/view_transaction. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (7.5) | 3.1% | — | CAR Dealer / Auto Dealer Responsive Project CAR Dealer / Auto Dealer Responsive | 11/10/2019 | 17/6/2026 | The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 1.2% | — | Brotherscripts Auto Dealer | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Select Development Solutions PHP Auto Dealer | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter. |