Vulnerabilities

Summary — last 7 days

New vulnerabilities2,772▲ 13 vs. last week
Critical / high1,288▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

268 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (5.5)0.41%—Janobe Water Billing System8/30/20256/17/2026
A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
AnalyzedMedium (5.5)0.41%—Janobe Water Billing System8/30/20256/17/2026
A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
AnalyzedMedium (5.5)0.41%—Oretnom23 Simple Cafe Billing System8/30/20256/17/2026
A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /sales_report.php. The manipulation of the argument month leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
AnalyzedMedium (5.5)0.41%—Oretnom23 Simple Cafe Billing System8/30/20256/17/2026
A vulnerability was determined in SourceCodester Simple Cafe Billing System 1.0. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalyzedMedium (5.5)0.55%—Campcodes Online Water Billing System8/26/20256/17/2026
A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the file /addclient1.php. Executing manipulation of the argument lname can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Other…
AnalyzedMedium (5.5)0.42%—Campcodes Online Water Billing System8/25/20256/17/2026
A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file /editecex.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AnalyzedMedium (5.5)0.42%💥 PoCCampcodes Online Water Billing System8/13/20256/17/2026
A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing of the file /viewbill.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalyzedHigh (8)0.41%💥 PoCMagnussolution Magnusbilling7/31/20256/17/2026
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
AnalyzedMedium (5.5)0.45%—Anisha Electricity Billing System7/14/20256/17/2026
A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/change_password.php. The manipulation of the argument new_password leads to sql injection. The attack may be launched remotely. The exploit has…
DeferredCritical (9.8)0.42%—Kashipara Billing SoftwareAI5/13/20256/17/2026
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.
AnalyzedMedium (4.8)0.37%—Fabian School Billing System4/29/20256/17/2026
A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public…
AnalyzedMedium (6)0.42%—Oracle Financial Services Revenue Management AND Billing4/15/20256/17/2026
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 5.1.0.0.0, 6.1.0.0.0 and 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via…
DeferredCritical (9.8)0.70%—Silverplugins217 Multiple Shipping AND Billing Address FOR WoocommerceAI4/1/20256/17/2026
Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows Object Injection.This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through <= 1.5.
DeferredMedium (6.5)0.29%—Zoho BillingAI3/27/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing – Embed Payment Form allows Stored XSS. This issue affects Zoho Billing – Embed Payment Form: from n/a through 4.0.
ModifiedMedium (5.4)0.94%💥 ExploitMagnussolution Magnusbilling3/21/20258/28/2026
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.
ModifiedMedium (6.1)1.1%💥 ExploitMagnussolution Magnusbilling3/21/20258/28/2026
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program…
DeferredCritical (9.3)0.37%—Silverplugins217 Multiple Shipping AND Billing Address FOR WoocommerceAI3/15/20256/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For…
AnalyzedMedium (4.8)0.35%—Razormist Telecom Billing Management System2/23/20256/17/2026
A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argument name/phonenumber leads to buffer overflow. Local access is required to…
DeferredCritical (9.3)0.40%—Silverplugins217 Different-shipping-and-billing-address-for-woocommerceAI1/7/20256/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For…
AnalyzedMedium (5.3)0.81%—Razormist Telecom Billing Management System9/22/20246/17/2026
A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of the argument uname leads to buffer overflow. The exploit has been disclosed to the public and may be used.
AnalyzedMedium (6.9)0.70%—Oretnom23 Electric Billing Management System8/30/20246/17/2026
A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalyzedMedium (5.3)0.62%—Oretnom23 Electric Billing Management System8/30/20246/17/2026
A vulnerability was found in SourceCodester Electric Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?page=tracks of the component Connection Code Handler. The manipulation of the argument code leads to sql injection. The attack may be…
AnalyzedMedium (6.9)0.58%—Angeljudesuarez Billing System8/18/20246/17/2026
A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. The manipulation of the argument lname/fname/mi/address/contact/meterReader leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalyzedMedium (6.9)0.62%—Angeljudesuarez Billing System8/15/20246/17/2026
A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AnalyzedMedium (5.3)0.58%—Oretnom23 Establishment Billing Management System7/31/20246/17/2026
A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view_bill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been…