Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.34%—Wpinventory WP Inventory ManagerAI18/9/202618/9/2026
The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in…
AplazadaAlta (7.1)0.25%—Wpinventory WP Inventory ManagerAI17/9/202617/9/2026
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
AplazadaAlta (8.5)0.36%—Wpinventory WP Inventory ManagerAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.
AplazadaMedia (5.1)0.33%—Online Inventory ManagerAI3/2/202617/6/2026
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side…
AplazadaMedia (4.3)0.15%—Wpinventory WP Inventory ManagerAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.
AplazadaMedia (6.1)0.29%—Wpinventory WP Inventory ManagerAI17/1/202517/6/2026
The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)0.46%—Ukrsolution Barcode Scanner AND Inventory Manager22/7/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from…
AnalizadaAlta (7.5)0.41%—Ukrsolution Barcode Scanner AND Inventory Manager9/6/202417/6/2026
Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
AplazadaAlta (8.8)0.61%—Barcode Scanner Inventory Manager POSAI2/5/202417/6/2026
The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack…
ModificadaCrítica (9.8)0.63%—Ukrsolution Barcode Scanner AND Inventory Manager24/1/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1.
ModificadaCrítica (9.8)0.55%—Ukrsolution Barcode Scanner AND Inventory Manager8/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For…
ModificadaAlta (8.8)0.30%—Wpinventory WP Inventory Manager9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.
ModificadaMedia (6.1)1.2%—Wpinventory WP Inventory Manager16/8/202317/6/2026
The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
ModificadaAlta (8.1)0.35%—Wpinventory WP Inventory Manager27/6/202317/6/2026
The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack
ModificadaMedia (6.1)0.46%—Wpinventory WP Inventory Manager8/5/202317/6/2026
The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
ModificadaMedia (5.5)0.79%—SAP Work ManagerSAP Inventory Manager12/6/201917/6/2026
SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
ModificadaAlta (7.5)4.0%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager27/4/200716/6/2026
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
ModificadaAlta (7.8)1.9%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager27/4/200716/6/2026
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
ModificadaMedia (6.8)1.4%—Website Designs FOR Less Inventory Manager17/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter.
ModificadaAlta (7.5)1.1%—Website Designs FOR Less Inventory Manager17/11/200616/6/2026
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.