Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.45% | — | Feminer Warehouse Management System | 17/1/2026 | 17/6/2026 | A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknown functionality of the file /src/chkuser.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Alta (8.1) | 0.79% | — | Yeqifu Warehouse Management System | 5/12/2025 | 25/9/2026 | Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authenticated attacker can… | |
| Analizada | Alta (7.5) | 0.70% | — | Yeqifu Warehouse Management System | 5/12/2025 | 25/9/2026 | The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system. This could lead to the leakage of… | |
| Analizada | Media (6.9) | 0.54% | — | Yangshare Warehouse Management System | 26/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Zeqp Wms-warehouse Management SystemAI | 2/12/2024 | 17/6/2026 | Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused. | |
| Analizada | Media (5.4) | 0.59% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Warehouse Management System 1.0. This vulnerability affects unknown code of the file pengguna.php. The manipulation of the argument admin_user/admin_nama/admin_alamat/admin_telepon leads to cross site scripting. The attack can be initiated remotely.… | |
| Analizada | Media (5.4) | 0.59% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Warehouse Management System 1.0. This affects an unknown part of the file customer.php. The manipulation of the argument nama_customer/alamat_customer/notelp_customer leads to cross site scripting. It is possible to initiate the attack… | |
| Analizada | Media (5.4) | 0.55% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file supplier.php. The manipulation of the argument nama_supplier/alamat_supplier/notelp_supplier leads to cross site scripting. The attack may be… | |
| Analizada | Media (5.4) | 0.55% | — | Oretnom23 Warehouse Management System | 11/4/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file barang.php. The manipulation of the argument nama_barang/merek leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 0.84% | — | Warehouse Management System Project Warehouse Management System | 3/12/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.95% | — | Oretnom23 Warehouse Management System | 26/7/2022 | 17/6/2026 | Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Retail Warehouse Management System | 24/4/2017 | 17/6/2026 | Vulnerability in the Oracle Retail Warehouse Management System component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13.2, 14.0 and 15.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail… |