Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.83% | — | Cafe Billing System Project Cafe Billing System | 28/7/2023 | 17/6/2026 | A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.44% | — | Water Billing System Project Water Billing System | 27/3/2023 | 17/6/2026 | SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module. | |
| Modificada | Crítica (9.8) | 0.83% | — | Billing System Project Project Billing System Project | 23/11/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. | |
| Modificada | Crítica (9.8) | 0.91% | — | Billing System Project Project Project Billing System Project | 22/11/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. | |
| Modificada | Crítica (9.8) | 0.91% | — | Billing System Project Billing System | 22/11/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Billing System Project Billing System | 22/11/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. | |
| Modificada | Alta (7.2) | 1.2% | — | Billing System Project Billing System | 18/10/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.2) | 0.78% | — | Billing System Project Billing System | 17/10/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. | |
| Modificada | Alta (7.2) | 0.86% | — | Billing System Project Project Billing System Project | 30/9/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | |
| Modificada | Alta (7.2) | 0.86% | — | Billing System Project Project Billing System Project | 30/9/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | |
| Modificada | Alta (7.2) | 1.7% | — | Billing System Project Project Billing System Project | 30/9/2022 | 17/6/2026 | Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. | |
| Modificada | Crítica (9.8) | 0.61% | — | Automated Beer Parlour Billing System Project Automated Beer Parlour Billing System | 12/8/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Modificada | Media (5.4) | 0.50% | — | Water Billing System Project Water Billing System | 24/5/2022 | 17/6/2026 | Water-billing-management-system v1.0 is affected by: Cross Site Scripting (XSS) via /wbms/classes/Users.php?f=save, firstname. | |
| Modificada | Crítica (9.8) | 1.1% | — | Water Billing System Project Water Billing System | 24/5/2022 | 17/6/2026 | Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id | |
| Modificada | Crítica (9.8) | 1.1% | — | Water Billing System Project Water Billing System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. | |
| Modificada | Crítica (9.8) | 2.6% | — | Water Billing System Project Water Billing System | 17/11/2020 | 17/6/2026 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php. |