🚨 CVE-2026-8474
A vulnerability was discovered on Stormshield Network Security
* 4.3.0 to 4.3.41,
* 4.8.0 to 4.8.15,
* 5.0.0 to 5.0.5
It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page behavior, for example, by redirecting the victim to malicious websites.
🎖@cveNotify
A vulnerability was discovered on Stormshield Network Security
* 4.3.0 to 4.3.41,
* 4.8.0 to 4.8.15,
* 5.0.0 to 5.0.5
It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page behavior, for example, by redirecting the victim to malicious websites.
🎖@cveNotify
🚨 CVE-2026-9024
A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.
🎖@cveNotify
A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.
🎖@cveNotify
Dassault Systèmes
CVE-2026-9024 - Dassault Systèmes
Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x
🚨 CVE-2026-10244
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.
🎖@cveNotify
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.
🎖@cveNotify
GitHub
sourcecodester Pharmacy Sales and Inventory System Project V1.0 ShowForm/create_medicine_name/main cross site scripting · Issue…
sourcecodester Pharmacy Sales and Inventory System Project V1.0 ShowForm/create_medicine_name/main cross site scripting Email OF AFFECTED PRODUCT(S) . Pharmacy Sales and Inventory System Vendor Hom...
🚨 CVE-2026-10245
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.
🎖@cveNotify
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.
🎖@cveNotify
GitHub
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/create_supplier/main cross site scripting · Issue #3…
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/create_supplier/main cross site scripting Email OF AFFECTED PRODUCT(S) . Pharmacy Sales and Inventory System Vendor Homepag...
🚨 CVE-2026-10246
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
🎖@cveNotify
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
🎖@cveNotify
GitHub
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/create_medicine_presentation/main cross site scripting…
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/create_medicine_presentation/main cross site scripting Email OF AFFECTED PRODUCT(S) . Pharmacy Sales and Inventory System V...
🚨 CVE-2026-10247
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.
🎖@cveNotify
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.
🎖@cveNotify
GitHub
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/create_generic_name/main cross site scripting · Issue…
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/create_generic_name/main cross site scripting Email OF AFFECTED PRODUCT(S) . Pharmacy Sales and Inventory System Vendor Hom...
🚨 CVE-2026-10248
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
🎖@cveNotify
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
🎖@cveNotify
GitHub
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /Export_csv/export CSV Injection · Issue #6 · timeflies123/cve
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /Export_csv/export CSV Injection NAME OF AFFECTED PRODUCT(S) . Pharmacy Sales and Inventory System Vendor Homepage sourcecodester sub...
🚨 CVE-2026-10249
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
🎖@cveNotify
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
🎖@cveNotify
GitHub
Online Blood Bank Management System V1.0 /viewrequest.php SQL injection · Issue #1 · zhengdexu-bot/zhengdexu
NAME OF AFFECTED PRODUCT(S) Online Blood Bank Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/online-blood-bank-management-system-in-php-with-source-code/ AFFEC...
🚨 CVE-2026-10250
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
GitHub
Online Blood Bank Management System V1.0 /campsdetails.php SQL injection · Issue #2 · zhengdexu-bot/zhengdexu
NAME OF AFFECTED PRODUCT(S) Online Blood Bank Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/online-blood-bank-management-system-in-php-with-source-code/ AFFEC...
🚨 CVE-2026-25599
Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an
unencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an
attacker to impersonate a legitimate device and inject malicious
payloads. This enables the insertion of harmful code directly
into the Orca user portal, potentially compromising user accounts,
exposing sensitive information, and allowing further unauthorized
actions within the portal.
🎖@cveNotify
Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an
unencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an
attacker to impersonate a legitimate device and inject malicious
payloads. This enables the insertion of harmful code directly
into the Orca user portal, potentially compromising user accounts,
exposing sensitive information, and allowing further unauthorized
actions within the portal.
🎖@cveNotify
SI CERT
CVE-2026-25599 – Missing authentication and clear‑text data transmission of Orca heat pumps - SI CERT
Summary Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored …
🚨 CVE-2026-25600
The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable. This secret is used by the application’s
encryption routines, including the function responsible for decrypting
credentials stored in the product’s configuration file. Because the
secret is constant across installations, any attacker with sufficient
local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored
password and authenticate as the user defined in the configuration file.
In the affected version, this user account is configured with
administrative privileges, granting full access to PDBM’s management
interface and its underlying operational functions.
🎖@cveNotify
The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable. This secret is used by the application’s
encryption routines, including the function responsible for decrypting
credentials stored in the product’s configuration file. Because the
secret is constant across installations, any attacker with sufficient
local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored
password and authenticate as the user defined in the configuration file.
In the affected version, this user account is configured with
administrative privileges, granting full access to PDBM’s management
interface and its underlying operational functions.
🎖@cveNotify
SI CERT
CVE-2026-25600 — Credential Exposure Vulnerability in Trac PDBM - SI CERT
Summary A vulnerability has been identified in Trac d.o.o. Process Database Manager (PDBM). The application contains a hard‑coded cryptographic secret embedded directly within the executable binary. This secret is used …
🚨 CVE-2026-49328
Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.
🎖@cveNotify
Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.
🎖@cveNotify
fesod.apache.org
Download | Apache Fesod (Incubating)
<!--
🚨 CVE-2026-10251
A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
🎖@cveNotify
A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
🎖@cveNotify
GitHub
Online House Rental System V1.0 /ajax.php SQL injection · Issue #3 · zhengdexu-bot/zhengdexu
NAME OF AFFECTED PRODUCT(S) Online House Rental System Vendor Homepage https://itsourcecode.com/free-projects/php-project/online-blood-bank-management-system-in-php-with-source-code/ AFFECTED AND/O...
🚨 CVE-2026-10252
A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
🎖@cveNotify
A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
🎖@cveNotify
GitHub
Online House Rental System V1.0 /manage_tenant.php SQL injection · Issue #4 · zhengdexu-bot/zhengdexu
NAME OF AFFECTED PRODUCT(S) Online House Rental System Vendor Homepage https://itsourcecode.com/free-projects/php-project/online-blood-bank-management-system-in-php-with-source-code/ AFFECTED AND/O...
🚨 CVE-2026-10253
A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
🎖@cveNotify
A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
🎖@cveNotify
GitHub
Online House Rental System V1.0 /manage_payment.php SQL injection · Issue #5 · zhengdexu-bot/zhengdexu
NAME OF AFFECTED PRODUCT(S) Online House Rental System Vendor Homepage https://itsourcecode.com/free-projects/php-project/online-blood-bank-management-system-in-php-with-source-code/ AFFECTED AND/O...
🚨 CVE-2026-10254
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.
🎖@cveNotify
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.
🎖@cveNotify
GitHub
Pet grooming management software -Directory traversal · Issue #2 · MICHEY-Ben/cve
Pet grooming management software -Directory traversal Exploit Title: Pet grooming management software - Directory traversal Contributor's Name:Zheng Yunpeng Contributor Units:School of Cyberspa...
🚨 CVE-2026-10255
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
🎖@cveNotify
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
🎖@cveNotify
GitHub
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/sell_statement/main Broken Access Control leading to…
sourcecodester Pharmacy Sales and Inventory System Project V1.0 /ShowForm/sell_statement/main Broken Access Control leading to Information Disclosure Email OF AFFECTED PRODUCT(S) . Pharmacy Sales a...
🚨 CVE-2026-10256
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
🎖@cveNotify
A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
🎖@cveNotify
GitHub
itsourcecode Content Management System V1.0 SQL Injection Vulnerability · Issue #1 · wsjjllk/cve
itsourcecode Content Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Content Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/cont...
🚨 CVE-2026-10257
A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
GitHub
itsourcecode Content Management System V1.0 SQL Injection Vulnerability · Issue #1 · Zorinman/cve
itsourcecode Content Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Content Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/cont...
🚨 CVE-2026-10532
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.
Although deserialization is heavily restricted by HardenedObjectInputStream and no
practical way to achieve remote code execution or significant privilege
escalation has been identified, this issue constitutes a bypass of the
intended security restrictions.
This issue affects logback: through 1.5.33 inclusive.
🎖@cveNotify
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.
More precisely, an attacker able to influence serialized data sent to
SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.
Although deserialization is heavily restricted by HardenedObjectInputStream and no
practical way to achieve remote code execution or significant privilege
escalation has been identified, this issue constitutes a bypass of the
intended security restrictions.
This issue affects logback: through 1.5.33 inclusive.
🎖@cveNotify
🚨 CVE-2026-34193
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.
🎖@cveNotify
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.
🎖@cveNotify
Imagination
Imagination GPU Driver Vulnerabilities - Imagination
This page contains summary details of security vulnerabilities reported on Imagination Technologies Power VR Graphics driver.