Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.50% | — | Itsourcecode Online Medicine Delivery SystemAI | 3/9/2026 | 4/9/2026 | A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument image results in unrestricted upload. Remote… | |
| Aplazada | Baja (2) | 0.35% | — | Itsourcecode Online Medicine Delivery SystemAI | 3/9/2026 | 5/9/2026 | A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.3) | 0.33% | — | Itsourcecode Online Medicine Delivery SystemAI | 3/9/2026 | 15/9/2026 | A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely. | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Medicine Delivery SystemAI | 3/9/2026 | 4/9/2026 | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It… | |
| Aplazada | Baja (2.1) | 0.37% | — | Itsourcecode Online Medicine Delivery SystemAI | 3/9/2026 | 4/9/2026 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument photo can lead to unrestricted upload. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Medicine Delivery SystemAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component Password Recovery Interface. The manipulation of the argument phonenumber leads to sql injection. Remote exploitation of the attack… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Medicine Delivery SystemAI | 31/8/2026 | 1/9/2026 | A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.php?q=product of the component Product Category Filter Interface. Executing a manipulation of the argument Category can lead to sql injection. The attack may be launched… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Medicine Delivery SystemAI | 31/8/2026 | 31/8/2026 | A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search Interface. Performing a manipulation of the argument Search results in sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Medicine Delivery SystemAI | 31/8/2026 | 31/8/2026 | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql injection. The attack can be launched… | |
| Aplazada | Media (5.5) | 0.56% | — | Itsourcecode Online Medicine Delivery SystemAI | 31/8/2026 | 31/8/2026 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated… | |
| Aplazada | Media (5.5) | 0.56% | — | Itsourcecode Online Medicine Delivery SystemAI | 31/8/2026 | 31/8/2026 | A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of the file /rider/login.php of the component Login Interface. The manipulation of the argument emp_email results in sql injection. It is possible to launch the attack… |