Vulnerabilities

Summary — last 7 days

New vulnerabilities2,623▼ 237 vs. last week
Critical / high1,384▲ 151 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 473 vs. last week
–

20 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.34%—Wpinventory WP Inventory ManagerAI9/18/20269/18/2026
The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in…
DeferredHigh (7.1)0.25%—Wpinventory WP Inventory ManagerAI9/17/20269/17/2026
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
DeferredHigh (8.5)0.36%—Wpinventory WP Inventory ManagerAI7/13/20267/13/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.
DeferredMedium (5.1)0.33%—Online Inventory ManagerAI2/3/20266/17/2026
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side…
DeferredMedium (4.3)0.15%—Wpinventory WP Inventory ManagerAI6/20/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.
DeferredMedium (6.1)0.29%—Wpinventory WP Inventory ManagerAI1/17/20256/17/2026
The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModifiedHigh (8.8)0.46%—Ukrsolution Barcode Scanner AND Inventory Manager7/22/20246/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from…
AnalyzedHigh (7.5)0.41%—Ukrsolution Barcode Scanner AND Inventory Manager6/9/20246/17/2026
Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
DeferredHigh (8.8)0.61%—Barcode Scanner Inventory Manager POSAI5/2/20246/17/2026
The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack…
ModifiedCritical (9.8)0.63%—Ukrsolution Barcode Scanner AND Inventory Manager1/24/20246/17/2026
Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1.
ModifiedCritical (9.8)0.55%—Ukrsolution Barcode Scanner AND Inventory Manager1/8/20246/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For…
ModifiedHigh (8.8)0.30%—Wpinventory WP Inventory Manager11/9/20236/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.
ModifiedMedium (6.1)1.2%—Wpinventory WP Inventory Manager8/16/20236/17/2026
The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
ModifiedHigh (8.1)0.35%—Wpinventory WP Inventory Manager6/27/20236/17/2026
The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack
ModifiedMedium (6.1)0.46%—Wpinventory WP Inventory Manager5/8/20236/17/2026
The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
ModifiedMedium (5.5)0.79%—SAP Work ManagerSAP Inventory Manager6/12/20196/17/2026
SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
ModifiedHigh (7.5)4.0%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager4/27/20076/16/2026
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
ModifiedHigh (7.8)1.9%—Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager4/27/20076/16/2026
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
ModifiedMedium (6.8)1.4%—Website Designs FOR Less Inventory Manager11/17/20066/16/2026
Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter.
ModifiedHigh (7.5)1.1%—Website Designs FOR Less Inventory Manager11/17/20066/16/2026
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.