Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.1% | — | Feminer WMS Project Feminer WMS | 14/2/2025 | 17/6/2026 | Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component. | |
| Analizada | Alta (7.5) | 0.49% | — | Feminer WMS Project Feminer WMS | 14/2/2025 | 17/6/2026 | SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id. | |
| Analizada | Media (5.1) | 0.27% | — | Feminer WMS Project Feminer WMS | 14/2/2025 | 17/6/2026 | SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid." | |
| Analizada | Media (5.1) | 0.27% | — | Feminer WMS Project Feminer WMS | 14/2/2025 | 17/6/2026 | SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component. | |
| Modificada | Crítica (9.8) | 1.0% | — | WMS Project WMS | 17/2/2023 | 17/6/2026 | An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function. | |
| Modificada | Crítica (9.8) | 2.7% | — | Feminer WMS Project Feminer WMS | 16/5/2022 | 17/6/2026 | A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec. | |
| Modificada | Crítica (9.8) | 0.99% | — | WMS Project WMS | 27/8/2021 | 17/6/2026 | The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection. | |
| Modificada | Crítica (9.8) | 2.3% | — | WMS Project WMS | 12/7/2021 | 17/6/2026 | SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php". |