Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.3% | — | Github ActionsAISherlockAI | 27/5/2026 | 17/6/2026 | Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the… | |
| Aplazada | Crítica (9.3) | 2.6% | — | Hgiga IsherlockAI | 16/4/2026 | 17/6/2026 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. | |
| Analizada | Media (5.5) | 0.57% | — | Sherlock Accounting System | 29/3/2026 | 17/6/2026 | A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.55% | — | Sherlock Accounting System | 29/3/2026 | 17/6/2026 | A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.57% | — | Sherlock Accounting System | 29/3/2026 | 17/6/2026 | A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remote. The exploit is… | |
| Aplazada | Crítica (9.3) | 1.8% | — | Hgiga IsherlockAI | 17/10/2025 | 17/6/2026 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. | |
| Aplazada | Crítica (9.3) | 1.4% | — | Hgiga IsherlockAI | 14/7/2025 | 17/6/2026 | The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Hgiga IsherlockAI | 8/4/2025 | 17/6/2026 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Hgiga IsherlockAI | 8/4/2025 | 17/6/2026 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Hgiga IsherlockAI | 8/4/2025 | 17/6/2026 | The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. | |
| Analizada | Alta (7.2) | 2.1% | — | Hgiga Isherlock | 29/4/2024 | 17/6/2026 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of… | |
| Analizada | Alta (7.2) | 2.1% | — | Hgiga Isherlock | 29/4/2024 | 17/6/2026 | The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary… | |
| Analizada | Media (4.9) | 0.67% | — | Hgiga Isherlock | 29/4/2024 | 17/6/2026 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files. | |
| Analizada | Media (4.9) | 0.67% | — | Hgiga Isherlock | 29/4/2024 | 17/6/2026 | The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files. | |
| Modificada | Crítica (9.8) | 0.71% | — | Sherlock Employee Management System | 14/2/2024 | 17/6/2026 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php. | |
| Modificada | Crítica (9.8) | 0.73% | — | Sherlock Employee Management System | 14/2/2024 | 17/6/2026 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php. | |
| Modificada | Crítica (9.8) | 0.98% | — | Sherlock Employee Management System | 14/2/2024 | 17/6/2026 | An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html. | |
| Modificada | Alta (7.2) | 0.72% | — | Sherlock Employee Management System | 14/2/2024 | 17/6/2026 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php. | |
| Modificada | Alta (7.2) | 0.72% | — | Sherlock Employee Management System | 14/2/2024 | 17/6/2026 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php. | |
| Modificada | Media (6.1) | 0.57% | — | Sherlock Online FIR System | 13/1/2024 | 17/6/2026 | A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.2% | — | Sherlock GYM Management System | 9/8/2023 | 17/6/2026 | Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL… | |
| Modificada | Crítica (9.8) | 1.3% | — | Hgiga Isherlock | 21/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before… | |
| Modificada | Media (5.3) | 0.60% | — | Hgiga Oaklouds Mailsherlock | 27/3/2023 | 17/6/2026 | HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL. | |
| Modificada | Alta (7.2) | 0.93% | — | Hgiga Oaklouds Mailsherlock | 27/3/2023 | 17/6/2026 | HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service. | |
| Modificada | Alta (7.2) | 0.93% | — | Hgiga Oaklouds Mailsherlock | 27/3/2023 | 17/6/2026 | HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database. |