Vulnerabilities
Summary — last 7 days
New vulnerabilities2,623▼ 237 vs. last week
Critical / high1,384▲ 151 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 473 vs. last week
20 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.34% | — | Wpinventory WP Inventory ManagerAI | 9/18/2026 | 9/18/2026 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in… | |
| Deferred | High (7.1) | 0.25% | — | Wpinventory WP Inventory ManagerAI | 9/17/2026 | 9/17/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | |
| Deferred | High (8.5) | 0.36% | — | Wpinventory WP Inventory ManagerAI | 7/13/2026 | 7/13/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0. | |
| Deferred | Medium (5.1) | 0.33% | — | Online Inventory ManagerAI | 2/3/2026 | 6/17/2026 | Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side… | |
| Deferred | Medium (4.3) | 0.15% | — | Wpinventory WP Inventory ManagerAI | 6/20/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4. | |
| Deferred | Medium (6.1) | 0.29% | — | Wpinventory WP Inventory ManagerAI | 1/17/2025 | 6/17/2026 | The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modified | High (8.8) | 0.46% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 7/22/2024 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Analyzed | High (7.5) | 0.41% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 6/9/2024 | 6/17/2026 | Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3. | |
| Deferred | High (8.8) | 0.61% | — | Barcode Scanner Inventory Manager POSAI | 5/2/2024 | 6/17/2026 | The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack… | |
| Modified | Critical (9.8) | 0.63% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 1/24/2024 | 6/17/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1. | |
| Modified | Critical (9.8) | 0.55% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 1/8/2024 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For… | |
| Modified | High (8.8) | 0.30% | — | Wpinventory WP Inventory Manager | 11/9/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions. | |
| Modified | Medium (6.1) | 1.2% | — | Wpinventory WP Inventory Manager | 8/16/2023 | 6/17/2026 | The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. | |
| Modified | High (8.1) | 0.35% | — | Wpinventory WP Inventory Manager | 6/27/2023 | 6/17/2026 | The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack | |
| Modified | Medium (6.1) | 0.46% | — | Wpinventory WP Inventory Manager | 5/8/2023 | 6/17/2026 | The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators. | |
| Modified | Medium (5.5) | 0.79% | — | SAP Work ManagerSAP Inventory Manager | 6/12/2019 | 6/17/2026 | SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | |
| Modified | High (7.5) | 4.0% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 4/27/2007 | 6/16/2026 | Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names. | |
| Modified | High (7.8) | 1.9% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 4/27/2007 | 6/16/2026 | The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field. | |
| Modified | Medium (6.8) | 1.4% | — | Website Designs FOR Less Inventory Manager | 11/17/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter. | |
| Modified | High (7.5) | 1.1% | — | Website Designs FOR Less Inventory Manager | 11/17/2006 | 6/16/2026 | Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter. |