Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)1.1%—Feminer WMS Project Feminer WMS14/2/202517/6/2026
Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.
AnalizadaAlta (7.5)0.49%—Feminer WMS Project Feminer WMS14/2/202517/6/2026
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.
AnalizadaMedia (5.1)0.27%—Feminer WMS Project Feminer WMS14/2/202517/6/2026
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."
AnalizadaMedia (5.1)0.27%—Feminer WMS Project Feminer WMS14/2/202517/6/2026
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.
ModificadaCrítica (9.8)1.0%—WMS Project WMS17/2/202317/6/2026
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
ModificadaCrítica (9.8)2.7%—Feminer WMS Project Feminer WMS16/5/202217/6/2026
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.
ModificadaCrítica (9.8)0.99%—WMS Project WMS27/8/202117/6/2026
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
ModificadaCrítica (9.8)2.3%—WMS Project WMS12/7/202117/6/2026
SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".