4.8

CVSS4.0

CVE-2026-6624 - BichitroGan ISP Billing Software Pool List add cross site scripting

A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been…

📅 Published: April 20, 2026, 9:15 a.m. 🔄 Last Modified: April 20, 2026, 9:15 a.m.

4.8

CVSS4.0

CVE-2026-6623 - BichitroGan ISP Billing Software Profile users-view cross site scripting

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out re…

📅 Published: April 20, 2026, 9 a.m. 🔄 Last Modified: April 20, 2026, 9 a.m.

5.1

CVSS4.0

CVE-2025-13480 - Incorrect authorization in Fudo Enterprise

Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protected API endpoints. This includes sensitive information such as system logs and parts of system configuration settings. This vulnerability has been fix…

📅 Published: April 20, 2026, 9 a.m. 🔄 Last Modified: April 20, 2026, 9 a.m.

4.8

CVSS4.0

CVE-2026-6622 - BichitroGan ISP Billing Software Customer edit cross site scripting

A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly avail…

📅 Published: April 20, 2026, 8:45 a.m. 🔄 Last Modified: April 20, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2026-6621 - 1024bit extend-deep index.js prototype pollution

A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. T…

📅 Published: April 20, 2026, 8:30 a.m. 🔄 Last Modified: April 20, 2026, 8:30 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here