5.3

CVSS4.0

CVE-2026-7265 - SourceCodester Pizzafy Ecommerce System index.php category sql injection

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit …

📅 Published: April 28, 2026, 10:30 a.m. 🔄 Last Modified: April 28, 2026, 10:30 a.m.

7.5

CVSS3.1

CVE-2026-3323 - VEGA: Privilege escalation through unsecured configuration interface in VEGAPULS devices

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

📅 Published: April 28, 2026, 10:24 a.m. 🔄 Last Modified: April 28, 2026, 10:24 a.m.

8.4

CVSS4.0

CVE-2026-7280 - eMPIA Technology|AVACAST - Unquoted Service Path

AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts.

📅 Published: April 28, 2026, 9:46 a.m. 🔄 Last Modified: April 28, 2026, 9:46 a.m.

8.5

CVSS4.0

CVE-2026-7279 - eMPIA Technology|AVACAST - DLL Hijacking

AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privileges when the system loads the DLL.

📅 Published: April 28, 2026, 9:39 a.m. 🔄 Last Modified: April 28, 2026, 9:39 a.m.

5.3

CVSS4.0

CVE-2026-7264 - SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been …

📅 Published: April 28, 2026, 9:30 a.m. 🔄 Last Modified: April 28, 2026, 9:30 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here