Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Multi Vendor Online Grocery Management SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_client of the file classes/Users.php of the component Registration Handler. The manipulation of the argument Name results in sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Multi-vendor Online Grocery Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this issue is the function cancel_order of the file classes/Master.php of the component POST Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to initiate the… | |
| Aplazada | Baja (2.1) | 0.40% | — | Sourcecodester Multi-vendor Online Grocery Management SystemAI | 5/7/2026 | 6/7/2026 | A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_order of the file classes/Master.php. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Multi-vendor Online Grocery Management SystemAI | 5/7/2026 | 6/7/2026 | A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.41% | — | Sourcecodester Multi-vendor Online Grocery Management SystemAI | 5/7/2026 | 6/7/2026 | A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[] leads to code injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Multi Vendor Online Grocery Management SystemAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and… |