|
2141
|
7.8 |
HIGH
Local
|
canonical
|
multipass
|
An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd da…
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-49237
|
2026-06-1 22:27 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2142
|
8.4 |
HIGH
Local
|
canonical
|
multipass
|
An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment …
|
CWE-22
Path Traversal
|
CVE-2026-49238
|
2026-06-1 22:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2143
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10244
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2144
|
3.5 |
LOW
Network
|
-
|
-
|
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipul…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10245
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2145
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/mai…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10246
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2146
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The ma…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10247
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2147
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplie…
|
CWE-74 CWE-1236
Injection Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-10248
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2148
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10249
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2149
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10250
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2150
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
|
CWE-79
Cross-site Scripting
|
CVE-2026-49368
|
2026-06-1 21:56 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|