Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.24% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published… | |
| Aplazada | Media (5.5) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 14/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper… | |
| Aplazada | Media (5.5) | 0.53% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 16/9/2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 10/9/2026 | A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.76% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 10/9/2026 | A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 11/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 14/9/2026 | A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible… | |
| Aplazada | Media (5.5) | 0.41% | — | Rabindralamsal Inventory-management-systemAI | 6/9/2026 | 8/9/2026 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Inventory-management-system-phpAI | 5/8/2026 | 26/8/2026 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Stock-inventory-management-systemAI | 5/8/2026 | 26/8/2026 | The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials… |