Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)1.3%—Github ActionsAISherlockAI27/5/202617/6/2026
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the…
AplazadaCrítica (9.3)2.6%—Hgiga IsherlockAI16/4/202617/6/2026
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
AnalizadaMedia (5.5)0.57%—Sherlock Accounting System29/3/202617/6/2026
A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.5)0.55%—Sherlock Accounting System29/3/202617/6/2026
A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.5)0.57%—Sherlock Accounting System29/3/202617/6/2026
A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remote. The exploit is…
AplazadaCrítica (9.3)1.8%—Hgiga IsherlockAI17/10/202517/6/2026
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.3)1.4%—Hgiga IsherlockAI14/7/202517/6/2026
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
AplazadaCrítica (9.8)1.3%—Hgiga IsherlockAI8/4/202517/6/2026
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.8)1.3%—Hgiga IsherlockAI8/4/202517/6/2026
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AplazadaCrítica (9.8)1.3%—Hgiga IsherlockAI8/4/202517/6/2026
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AnalizadaAlta (7.2)2.1%—Hgiga Isherlock29/4/202417/6/2026
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of…
AnalizadaAlta (7.2)2.1%—Hgiga Isherlock29/4/202417/6/2026
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary…
AnalizadaMedia (4.9)0.67%—Hgiga Isherlock29/4/202417/6/2026
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
AnalizadaMedia (4.9)0.67%—Hgiga Isherlock29/4/202417/6/2026
The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
ModificadaCrítica (9.8)0.71%—Sherlock Employee Management System14/2/202417/6/2026
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.
ModificadaCrítica (9.8)0.73%—Sherlock Employee Management System14/2/202417/6/2026
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.
ModificadaCrítica (9.8)0.98%—Sherlock Employee Management System14/2/202417/6/2026
An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.
ModificadaAlta (7.2)0.72%—Sherlock Employee Management System14/2/202417/6/2026
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.
ModificadaAlta (7.2)0.72%—Sherlock Employee Management System14/2/202417/6/2026
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
ModificadaMedia (6.1)0.57%—Sherlock Online FIR System13/1/202417/6/2026
A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)1.2%—Sherlock GYM Management System9/8/202317/6/2026
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL…
ModificadaCrítica (9.8)1.3%—Hgiga Isherlock21/7/202317/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before…
ModificadaMedia (5.3)0.60%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
ModificadaAlta (7.2)0.93%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
ModificadaAlta (7.2)0.93%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.