|
1041
|
3.7 |
LOW
Network
|
-
|
-
|
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
New
|
CWE-617
Reachable Assertion
|
CVE-2026-48852
|
2026-05-27 04:29 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1042
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation Handler…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9411
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1043
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access c…
New
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-9412
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1044
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. The manipulation of the argument msg lea…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9413
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1045
|
3.5 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing/add_order.php of the component Invoice …
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9414
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1046
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler.…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9444
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1047
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulati…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-9445
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1048
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argume…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9446
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1049
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Na…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9447
|
2026-05-27 04:26 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1050
|
8.1 |
HIGH
Network
|
-
|
-
|
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
New
|
CWE-89
SQL Injection
|
CVE-2026-48842
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|