Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.41% | — | Mayurik Free AND Open Source Inventory Management System | 29/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/action/add_staff.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.63% | — | Mayurik Free AND Open Source Inventory Management System | 27/2/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated… | |
| Modificada | Media (6.5) | 0.35% | — | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 30/1/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component. | |
| Modificada | Crítica (9.8) | 0.66% | — | Mayurik Free AND Open Source Inventory Management System | 29/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /app/ajax/sell_return_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack may be initiated… | |
| Modificada | Alta (8.8) | 0.63% | — | Mayurik Free AND Open Source Inventory Management System | 29/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Free and Open Source Inventory Management System 1.0. This affects an unknown part of the file /ample/app/action/edit_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Crítica (9.8) | 0.80% | — | Mayurik Free AND Open Source Inventory Management System | 27/11/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Free and Open Source Inventory Management System 1.0. Affected is an unknown function of the file /ample/app/ajax/member_data.php. The manipulation of the argument columns leads to sql injection. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.80% | — | Mayurik Free AND Open Source Inventory Management System | 27/11/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliar_data.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated… | |
| Modificada | Media (6.1) | 0.69% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 8/9/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section. | |
| Modificada | Media (6.1) | 0.64% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 7/9/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section. | |
| Modificada | Media (6.1) | 0.64% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 1/9/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section. | |
| Modificada | Media (6.1) | 0.64% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 1/9/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section. | |
| Modificada | Media (6.1) | 0.64% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 28/8/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section. | |
| Modificada | Media (6.1) | 0.64% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 28/8/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section. | |
| Modificada | Media (5.4) | 0.70% | 💥 PoC | Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System | 25/8/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section. |