Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.19%—Amirsanni Mini Inventory AND Sales Management SystemAI28/9/202628/9/2026
A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to…
AplazadaBaja (2.1)0.19%—Amirsanni Mini Inventory AND Sales Management SystemAI27/9/202628/9/2026
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results…
AplazadaBaja (2.1)0.33%—Amirsanni Mini-inventory-and-sales-management-systemAI20/8/202620/8/2026
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack…
AnalizadaMedia (5.5)0.44%—1000projects Sales Management System14/8/202517/6/2026
A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.5)0.51%—1000projects Sales Management System14/8/202517/6/2026
A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and…
AnalizadaBaja (2.1)0.41%—1000projects Sales Management System14/8/202517/6/2026
A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation of the argument select2112 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2.1)0.41%—1000projects Sales Management System14/8/202517/6/2026
A vulnerability was identified in 1000 Projects Sales Management System 1.0. This issue affects some unknown processing of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.5)0.51%—1000projects Sales Management System14/8/202517/6/2026
A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (6.9)0.75%—Codezips Sales Management System25/10/202417/6/2026
A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcustind.php. The manipulation of the argument refno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.81%—Codezips Sales Management System25/10/202417/6/2026
A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /addcustcom.php. The manipulation of the argument refno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaMedia (6.9)0.70%—Codezips Sales Management System25/10/202417/6/2026
A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.65%—Codezips Sales Management System20/10/202417/6/2026
A vulnerability classified as critical has been found in Codezips Sales Management System 1.0. This affects an unknown part of the file deletecustind.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (6.9)0.68%—Codezips Sales Management System20/10/202417/6/2026
A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file checkuser.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.70%—Codezips Sales Management System20/10/202417/6/2026
A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file deletecustcom.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
AplazadaMedia (5.4)0.25%—Mini Inventory AND Sales Management SystemAI21/8/202417/6/2026
A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
ModificadaMedia (6.1)0.53%—Simple Sales Management System Project Simple Sales Management System7/2/202317/6/2026
Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 sales management system 1.0, allows attackers to execute arbitrary code via the product_name and product_price inputs in file print.php.
ModificadaMedia (5.4)0.59%—Simple Sales Management System Project Simple Sales Management System12/7/202217/6/2026
A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manipulation of the argument customer_name with the input <script>alert("XSS")</script> leads to cross…
ModificadaMedia (5)0.32%—Mini-inventory-and-sales-management-system Project Mini-inventory-and-sales-management-system4/3/202217/6/2026
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.
ModificadaCrítica (9.8)1.5%—Phone Shop Sales Management System Project Phone Shop Sales Management System2/11/202117/6/2026
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.
ModificadaCrítica (9.8)1.8%—Phone Shop Sales Management System Project Phone Shop Sales Management System3/8/202117/6/2026
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
ModificadaCrítica (9.8)3.4%—Phone Shop Sales Management System Project Phone Shop Sales Management System30/7/202117/6/2026
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
ModificadaMedia (4.3)0.82%—Phone Shop Sales Management System Project Phone Shop Sales Management System1/7/202117/6/2026
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
ModificadaCrítica (9.8)2.1%💥 ExploitVehicle Sales Management System Project Vehicle Sales Management System24/1/201817/6/2026
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability,…