|
2511
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cro…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8218
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2512
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. The impacted element is an unknown function of the file /inventory/supplier-save. The manipulation leads to cross sit…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8219
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2513
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8220
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2514
|
2.4 |
LOW
Network
|
-
|
-
|
A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible t…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8221
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2515
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation lea…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-8241
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2516
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-8243
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2517
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results…
|
CWE-203 CWE-204
Information Exposure Through Discrepancy Response Discrepancy Information Exposure
|
CVE-2026-8242
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2518
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVe…
|
CWE-287
Improper Authentication
|
CVE-2026-8244
|
2026-05-12 00:08 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2519
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8253
|
2026-05-12 00:08 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2520
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross si…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-8254
|
2026-05-12 00:08 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|