Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

210 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.41%—Sourcecodester Inventory Management SystemAI14/9/202615/9/2026
A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
AplazadaBaja (2)0.35%—Sourcecodester Inventory Management SystemAI14/9/202614/9/2026
A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may…
AplazadaBaja (2)0.35%—Sourcecodester Inventory Management SystemAI14/9/202616/9/2026
A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely.…
AplazadaBaja (2)0.35%—Sourcecodester Inventory Management SystemAI14/9/202614/9/2026
A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Customer_Name leads to cross site scripting. The attack can be executed remotely. The…
AplazadaBaja (2.1)0.24%—Rizwan17 Inventory-management-systemAI13/9/202614/9/2026
A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published…
AplazadaMedia (5.5)0.47%—Rizwan17 Inventory-management-systemAI13/9/202614/9/2026
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper…
AplazadaMedia (5.5)0.53%—Rizwan17 Inventory-management-systemAI13/9/202616/9/2026
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely.…
AplazadaBaja (2.1)0.47%—Rizwan17 Inventory-management-systemAI10/9/202614/9/2026
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely.…
AplazadaMedia (5.5)0.43%—Rizwan17 Inventory-management-systemAI10/9/202610/9/2026
A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be…
AplazadaMedia (5.5)0.76%—Rizwan17 Inventory-management-systemAI9/9/202610/9/2026
A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing…
AplazadaBaja (2.1)0.47%—Rizwan17 Inventory-management-systemAI9/9/202611/9/2026
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes…
AplazadaMedia (5.5)0.69%—Rizwan17 Inventory Management SystemAI9/9/202610/9/2026
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing…
AplazadaMedia (5.5)0.43%—Rizwan17 Inventory-management-systemAI9/9/202614/9/2026
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible…
AplazadaMedia (5.5)0.41%—Rabindralamsal Inventory-management-systemAI6/9/20268/9/2026
A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AnalizadaAlta (7.4)0.34%—Oracle Communications Unified Inventory Management18/8/202625/8/2026
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Third Party). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0-7.8.0 and 8.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaAlta (7.5)0.41%—Oracle Communications Unified Inventory Management18/8/202625/8/2026
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security Component). Supported versions that are affected are 7.5.0-7.5.1, 7.6.0-7.8.0 and 8.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
AplazadaCrítica (9.8)0.75%—Inventory-management-system-phpAI5/8/202626/8/2026
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -.
AplazadaCrítica (9.8)0.71%—Stock-inventory-management-systemAI5/8/202626/8/2026
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials…
AnalizadaAlta (7.1)0.30%—Oracle Communications Unified Inventory Management21/7/202617/8/2026
Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security). Supported versions that are affected are 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0 and 8.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
AnalizadaAlta (7.5)0.13%—Oracle Peoplesoft Enterprise SCM Mobile Inventory Management21/7/20266/8/2026
Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise SCM Mobile…
AnalizadaBaja (1.9)0.14%—Oracle Inventory Management21/7/20264/8/2026
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes…
AnalizadaMedia (6.4)0.15%—Oracle Inventory Management21/7/20263/8/2026
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes…
AnalizadaAlta (7.7)0.39%—Oracle Inventory Management21/7/20263/8/2026
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. While…
AnalizadaAlta (8.1)0.36%—Oracle Inventory Management21/7/20266/8/2026
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful…
AplazadaBaja (2)0.33%—Sourcecodester Inventory Management SystemAI29/6/202629/6/2026
A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting. The attack is possible to be carried out…