5.3

CVSS4.0

CVE-2026-7391 - SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publish…

πŸ“… Published: April 29, 2026, 4:15 p.m. πŸ”„ Last Modified: April 30, 2026, 1:01 p.m.

7.5

CVSS3.1

CVE-2026-42198 - pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. …

πŸ“… Published: April 29, 2026, 3:58 p.m. πŸ”„ Last Modified: May 1, 2026, 12:51 p.m.

5.1

CVSS4.0

CVE-2026-7390 - SourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function Customer of the file /index.php?page=customer. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now …

πŸ“… Published: April 29, 2026, 3:45 p.m. πŸ”„ Last Modified: April 29, 2026, 3:45 p.m.

4.8

CVSS4.0

CVE-2026-40230 - Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0.

πŸ“… Published: April 29, 2026, 3:39 p.m. πŸ”„ Last Modified: May 1, 2026, 12:26 p.m.

5.1

CVSS4.0

CVE-2026-40229 - Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notific…

πŸ“… Published: April 29, 2026, 3:34 p.m. πŸ”„ Last Modified: April 29, 2026, 3:34 p.m.

6.9

CVSS4.0

CVE-2026-7389 - EyouCMS common.php GetSortData sql injection

A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and…

πŸ“… Published: April 29, 2026, 3:30 p.m. πŸ”„ Last Modified: April 29, 2026, 4:19 p.m.

6.8

CVSS4.0

CVE-2026-2810 - Endpoint DLP Driver Out-of-Bounds Read

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exp…

πŸ“… Published: April 29, 2026, 3:23 p.m. πŸ”„ Last Modified: April 30, 2026, 8:21 a.m.

5.1

CVSS4.0

CVE-2026-7388 - EyouCMS Template File FilemanagerLogic.php editFile code injection

A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been ma…

πŸ“… Published: April 29, 2026, 3:15 p.m. πŸ”„ Last Modified: April 29, 2026, 6:32 p.m.

9.3

CVSS4.0

CVE-2026-41940 - WebPros cPanel and WHM Authentication Bypass via Login Flow

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

πŸ“… Published: April 29, 2026, 3:10 p.m. πŸ”„ Last Modified: May 4, 2026, 5:16 p.m.

6.9

CVSS4.0

CVE-2026-7386 - fatbobman mail-mcp-bridge mail_mcp_server.py path traversal

A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manipulation of the argument message_ids can lead to path traversal. The attack can be executed remotely. The exploit has been published and may be used. U…

πŸ“… Published: April 29, 2026, 3 p.m. πŸ”„ Last Modified: April 30, 2026, 8:21 a.m.
Total resulsts: 349182
Page 204 of 34,919
Β« previous page Β» next page
Filters