Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Client Management SystemAI | 14/8/2026 | 14/8/2026 | A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.72% | — | Simple Client Management System Project Simple Client Management System | 22/12/2022 | 17/6/2026 | A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields. | |
| Modificada | Crítica (9.8) | 1.7% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=. | |
| Modificada | Crítica (9.8) | 1.7% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 12/5/2022 | 17/6/2026 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id. | |
| Modificada | Crítica (9.8) | 3.5% | — | Simple Client Management System Project Simple Client Management System | 31/3/2022 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Client Management System Project Simple Client Management System | 31/3/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php. | |
| Modificada | Media (5.4) | 0.55% | — | Simple Client Management System Project Simple Client Management System | 31/3/2022 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice. | |
| Modificada | Crítica (9.8) | 2.0% | — | Simple Client Management System Project Simple Client Management System | 21/3/2022 | 17/6/2026 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | |
| Modificada | Crítica (9.8) | 2.0% | — | Simple Client Management System Project Simple Client Management System | 21/3/2022 | 17/6/2026 | Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | |
| Modificada | Crítica (9.8) | 7.5% | — | Simple Client Management System Project Simple Client Management System | 1/2/2022 | 17/6/2026 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | |
| Modificada | Crítica (9.8) | 1.8% | — | Simple Client Management System Project Simple Client Management System | 1/2/2022 | 17/6/2026 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. |