Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.41%—Mayurik Free AND Open Source Inventory Management System29/9/202417/6/2026
A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/action/add_staff.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been…
AnalizadaCrítica (9.8)0.63%—Mayurik Free AND Open Source Inventory Management System27/2/202417/6/2026
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated…
ModificadaMedia (6.5)0.35%—Free AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System30/1/202417/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.
ModificadaCrítica (9.8)0.66%—Mayurik Free AND Open Source Inventory Management System29/12/202317/6/2026
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /app/ajax/sell_return_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack may be initiated…
ModificadaAlta (8.8)0.63%—Mayurik Free AND Open Source Inventory Management System29/12/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Free and Open Source Inventory Management System 1.0. This affects an unknown part of the file /ample/app/action/edit_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.…
ModificadaCrítica (9.8)0.80%—Mayurik Free AND Open Source Inventory Management System27/11/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Free and Open Source Inventory Management System 1.0. Affected is an unknown function of the file /ample/app/ajax/member_data.php. The manipulation of the argument columns leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.80%—Mayurik Free AND Open Source Inventory Management System27/11/202317/6/2026
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliar_data.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated…
ModificadaMedia (6.1)0.69%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System8/9/202317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.
ModificadaMedia (6.1)0.64%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System7/9/202317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
ModificadaMedia (6.1)0.64%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System1/9/202317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.
ModificadaMedia (6.1)0.64%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System1/9/202317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.
ModificadaMedia (6.1)0.64%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System28/8/202317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.
ModificadaMedia (6.1)0.64%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System28/8/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.
ModificadaMedia (5.4)0.70%💥 PoCFree AND Open Source Inventory Management System Project Free AND Open Source Inventory Management System25/8/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.
Orbitaley — Vulnerabilidades