Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.7)0.34%—Oretnom23 Pharmacy Point OF Sale System3/3/202617/6/2026
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.
AnalizadaBaja (2.7)0.34%—Oretnom23 Pharmacy Point OF Sale System3/3/202617/6/2026
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.
AnalizadaBaja (2.7)0.34%—Oretnom23 Pharmacy Point OF Sale System3/3/202617/6/2026
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.
AnalizadaBaja (2.7)0.34%—Oretnom23 Pharmacy Point OF Sale System3/3/202617/6/2026
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.
ModificadaCrítica (9.8)0.52%—Oretnom23 Pharmacy Point OF Sale System2/3/202617/6/2026
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
ModificadaCrítica (9.8)0.52%—Oretnom23 Pharmacy Point OF Sale System2/3/202617/6/2026
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
AnalizadaCrítica (9.8)0.52%—Oretnom23 Pharmacy Point OF Sale System2/3/202617/6/2026
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.
AnalizadaCrítica (9.8)0.52%—Oretnom23 Pharmacy Point OF Sale System2/3/202617/6/2026
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
AnalizadaCrítica (9.8)0.52%—Oretnom23 Pharmacy Point OF Sale System2/3/202617/6/2026
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.
AnalizadaMedia (5.5)0.50%—Campcodes Point OF Sale System23/9/202517/6/2026
A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown functionality of the file /login.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202517/6/2026
A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dymanic_table.php. Such manipulation of the argument scripts leads to cross site scripting. The attack may be…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202517/6/2026
A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_th.php. This manipulation of the argument scripts causes cross site scripting. The attack is possible to be carried out remotely.…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202517/6/2026
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts results in cross site scripting. The attack can be…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System7/9/202530/9/2026
A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Performing manipulation of the argument scripts results in cross site scripting. It is possible to initiate the…
AnalizadaBaja (2.1)0.40%—Facebook-kimmymatillano Point OF Sale System6/9/202530/9/2026
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site scripting. Remote exploitation of the attack is…
AnalizadaBaja (2)0.29%—Facebook-kimmymatillano Point OF Sale System6/9/202517/6/2026
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation of the argument scripts results in cross site scripting. The attack may be…
AnalizadaBaja (2)0.29%—Facebook-kimmymatillano Point OF Sale System6/9/202517/6/2026
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit is publicly…
AnalizadaBaja (2)0.30%—Facebook-kimmymatillano Point OF Sale System5/9/202517/6/2026
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts causes cross site scripting. The attack can be initiated remotely.…
AnalizadaBaja (2)0.29%—Facebook-kimmymatillano Point OF Sale System5/9/202517/6/2026
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument scripts results in cross site scripting. It is possible to…
AnalizadaCrítica (9.8)0.50%—Fkgeo Pharmacy/medical Store Point OF Sale System16/7/202417/6/2026
SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php.
ModificadaCrítica (9.8)0.52%—Pharmacy/medical Store Point OF Sale System Project Pharmacy/medical Store Point OF Sale System7/6/202417/6/2026
Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.
ModificadaMedia (6.1)0.45%—Oretnom23 POS - Point OF Sale System1/5/202417/6/2026
Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.
ModificadaCrítica (9.8)1.5%—Pharmacy Point OF Sale System Project Pharmacy Point OF Sale System29/10/202117/6/2026
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
ModificadaMedia (5.4)0.59%—Junhetec Enterprise Resource Planning Point OF Sale System7/5/202117/6/2026
Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
ModificadaMedia (5.4)0.59%—Junhetec Enterprise Resource Planning Point OF Sale System7/5/202117/6/2026
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.