|
1351
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The ma…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10247
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1352
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplie…
New
|
CWE-74 CWE-1236
Injection Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-10248
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1353
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10249
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1354
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10250
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1355
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-49368
|
2026-06-1 21:56 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1356
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-49369
|
2026-06-1 21:56 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1357
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
Update
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-49370
|
2026-06-1 21:52 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1358
|
6.1 |
MEDIUM
Network
|
jetbrains
|
pycharm
|
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-49384
|
2026-06-1 21:44 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1359
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
Update
|
CWE-862
Missing Authorization
|
CVE-2026-49385
|
2026-06-1 21:41 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1360
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49386
|
2026-06-1 21:40 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|