Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 15/9/2026 | A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 14/9/2026 | A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 16/9/2026 | A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester Inventory Management SystemAI | 14/9/2026 | 14/9/2026 | A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Customer_Name leads to cross site scripting. The attack can be executed remotely. The… | |
| Aplazada | Baja (2.1) | 0.24% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published… | |
| Aplazada | Media (5.5) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 14/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper… | |
| Aplazada | Media (5.5) | 0.53% | — | Rizwan17 Inventory-management-systemAI | 13/9/2026 | 16/9/2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 10/9/2026 | A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.76% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 10/9/2026 | A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 11/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes… | |
| Aplazada | Media (5.5) | 0.69% | — | Rizwan17 Inventory Management SystemAI | 9/9/2026 | 10/9/2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 14/9/2026 | A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible… | |
| Aplazada | Media (5.5) | 0.41% | — | Rabindralamsal Inventory-management-systemAI | 6/9/2026 | 8/9/2026 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Inventory-management-system-phpAI | 5/8/2026 | 26/8/2026 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Stock-inventory-management-systemAI | 5/8/2026 | 26/8/2026 | The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials… | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Inventory Management SystemAI | 29/6/2026 | 29/6/2026 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting. The attack is possible to be carried out… | |
| Aplazada | Media (5.5) | 0.47% | — | Sourcecodester Inventory Management SystemAI | 29/6/2026 | 1/7/2026 | A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls. Remote exploitation of the attack is… | |
| Aplazada | Baja (2.1) | 0.21% | — | Bdtask Multi-store Inventory Management SystemAI | 31/5/2026 | 22/7/2026 | A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted upload. The attack… | |
| Aplazada | Baja (2) | 0.21% | — | Bdtask Multi-store Inventory Management SystemAI | 31/5/2026 | 22/7/2026 | A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate results in sql… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Inventory Management SystemAI | 27/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Inventory Management System 1.0. Affected is an unknown function of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used… | |
| Analizada | Media (5.3) | 0.35% | — | Inventory Management System Project Inventory Management System | 15/12/2025 | 17/6/2026 | Inventory Management System 1 was discovered to contain a SQL injection vulnerability. | |
| Analizada | Media (6.1) | 0.22% | — | Inventory Management System Project Inventory Management System | 15/12/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Analizada | Baja (2) | 0.35% | — | Warren-daloyan Inventory Management System | 8/12/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.47% | — | Warren-daloyan Inventory Management System | 23/11/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The exploit has been made available to the public… |