|
371
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View P…
New
|
CWE-99
Resource Injection
|
CVE-2026-10624
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
372
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH Protocol Hand…
New
|
CWE-400 CWE-404
Uncontrolled Resource Consumption Improper Resource Shutdown or Release
|
CVE-2026-10650
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
373
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. T…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-10693
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
374
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in…
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-10694
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
375
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argum…
New
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-10692
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
376
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name`…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7421
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
377
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorr…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-9732
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
378
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS.
This issue affects Prague: from n/a through 2.2.8.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-15654
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
379
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection.
This issue affects School Management: from n/a …
New
|
CWE-89
SQL Injection
|
CVE-2025-15655
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
380
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation.
This issue affects School Management: from n/a through 93.2.0.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-15656
|
2026-06-4 22:53 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|