Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Crítica (9.1) | 0.65% | — | Lalanachami Pharmacy Management SystemAI | 19/5/2026 | 24/7/2026 | API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Lalanachami Pharmacy Management SystemAI | 19/5/2026 | 24/7/2026 | The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body | |
| Analizada | Baja (2.1) | 0.34% | — | Codeastro Simple Pharmacy Management System | 22/9/2025 | 17/6/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file /view.php. This manipulation of the argument bar_code causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 0.42% | — | Krishna9772 Pharmacy Management System | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file quantity_upd.php. The manipulation of the argument med_name/med_cat/ex_date leads to sql injection. It is possible to launch… | |
| Analizada | Media (4.8) | 0.35% | — | Code-projects Pharmacy Management System | 18/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. This affects the function medicineType::take_order of the component Add Order Details. The manipulation leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Codeastro Pharmacy Management System | 16/5/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.1) | 0.44% | — | Code-projects Pharmacy Management | 21/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /manage_medicine.php of the component Manage Medicines Page. The manipulation of the argument name/address/doctor_address/suppliers_name leads to… | |
| Analizada | Media (5.1) | 0.44% | — | Code-projects Pharmacy Management | 21/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /manage_customer.php of the component Manage Customer Page. The manipulation of the argument suppliers_name/address leads to cross site… | |
| Analizada | Media (5.1) | 0.41% | — | Code-projects Pharmacy Management System | 21/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /manage_supplier.php of the component Manage Supplier Page. The manipulation of the argument address leads to cross site scripting. It is possible to launch the… | |
| Analizada | Media (5.3) | 0.52% | — | Code-projects Pharmacy Management System | 21/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /add_new_invoice.php. The manipulation of the argument text leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 1.4% | — | Code-projects Pharmacy Management System | 19/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. Affected by this issue is some unknown functionality of the file /manage_supplier.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Pharmacy Management System | 19/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add_new_supplier.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Pharmacy Management System | 19/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. Affected is an unknown function of the file /add_new_purchase.php?action=is_supplier. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Pharmacy Management System | 19/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /manage_medicine.php?action=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Pharmacy Management System | 19/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. The manipulation of the argument invoice_number leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.61% | — | Code-projects Pharmacy Management System | 16/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This issue affects some unknown processing of the file /php/manage_medicine_stock.php. The manipulation of the argument name/packing/generic_name/suppliers_name leads to sql injection. The attack may be… | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Pharmacy Management System | 16/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /php/add_new_medicine.php. The manipulation of the argument name/packing/generic_name/suppliers_name leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.58% | — | Code-projects Pharmacy Management System | 16/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.58% | — | Code-projects Pharmacy Management System | 16/10/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /php/manage_purchase.php?action=search&tag=VOUCHER_NUMBER. The manipulation of the argument text leads to sql injection. The attack may be launched… | |
| Analizada | Media (5.3) | 0.52% | — | Code-projects Pharmacy Management System | 15/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.70% | — | Codezips Pharmacy Management System | 10/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an unknown function of the file product/update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.70% | — | Codezips Pharmacy Management System | 10/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file product/register.php. The manipulation of the argument category leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.53% | — | Code-projects Pharmacy Management System | 31/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit of the component Update My Profile Page. The manipulation of the argument fname/lname/email with the input <script>alert(1)</script>… |