Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.19% | — | Amirsanni Mini Inventory AND Sales Management SystemAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to… | |
| Aplazada | Baja (2.1) | 0.19% | — | Amirsanni Mini Inventory AND Sales Management SystemAI | 27/9/2026 | 28/9/2026 | A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results… | |
| Aplazada | Baja (2.1) | 0.33% | — | Amirsanni Mini-inventory-and-sales-management-systemAI | 20/8/2026 | 20/8/2026 | A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack… | |
| Analizada | Media (5.5) | 0.44% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.51% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (2.1) | 0.41% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation of the argument select2112 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.41% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was identified in 1000 Projects Sales Management System 1.0. This issue affects some unknown processing of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.51% | — | 1000projects Sales Management System | 14/8/2025 | 17/6/2026 | A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.75% | — | Codezips Sales Management System | 25/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcustind.php. The manipulation of the argument refno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.81% | — | Codezips Sales Management System | 25/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /addcustcom.php. The manipulation of the argument refno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.70% | — | Codezips Sales Management System | 25/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.65% | — | Codezips Sales Management System | 20/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Codezips Sales Management System 1.0. This affects an unknown part of the file deletecustind.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.68% | — | Codezips Sales Management System | 20/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file checkuser.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.70% | — | Codezips Sales Management System | 20/10/2024 | 17/6/2026 | A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file deletecustcom.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.4) | 0.25% | — | Mini Inventory AND Sales Management SystemAI | 21/8/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter. | |
| Modificada | Media (6.1) | 0.53% | — | Simple Sales Management System Project Simple Sales Management System | 7/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 sales management system 1.0, allows attackers to execute arbitrary code via the product_name and product_price inputs in file print.php. | |
| Modificada | Media (5.4) | 0.59% | — | Simple Sales Management System Project Simple Sales Management System | 12/7/2022 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manipulation of the argument customer_name with the input <script>alert("XSS")</script> leads to cross… | |
| Modificada | Media (5) | 0.32% | — | Mini-inventory-and-sales-management-system Project Mini-inventory-and-sales-management-system | 4/3/2022 | 17/6/2026 | Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items. | |
| Modificada | Crítica (9.8) | 1.5% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 2/11/2021 | 17/6/2026 | Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin. | |
| Modificada | Crítica (9.8) | 1.8% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 3/8/2021 | 17/6/2026 | Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE. | |
| Modificada | Crítica (9.8) | 3.4% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 30/7/2021 | 17/6/2026 | Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. | |
| Modificada | Media (4.3) | 0.82% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 1/7/2021 | 17/6/2026 | Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 Exploit | Vehicle Sales Management System Project Vehicle Sales Management System | 24/1/2018 | 17/6/2026 | Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability,… |