Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▲ 13 vs. last week
Critical / high1,289▼ 241 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
268 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (5.3) | 0.62% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_billing.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The… | |
| Analyzed | Medium (5.3) | 0.62% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Establishment Billing Management System 1.0. Affected is an unknown function of the file /manage_block.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analyzed | Medium (5.3) | 0.53% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability classified as critical has been found in SourceCodester Establishment Billing Management System 1.0. This affects an unknown part of the file /manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analyzed | Medium (5.3) | 0.58% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /manage_payment.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analyzed | Medium (5.3) | 0.53% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_block. The manipulation of the argument id leads to sql injection. The attack can be launched… | |
| Analyzed | Medium (5.3) | 0.53% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analyzed | Medium (6.9) | 0.65% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated… | |
| Analyzed | Medium (5.3) | 0.45% | — | Oretnom23 Establishment Billing Management System | 7/31/2024 | 6/17/2026 | A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated… | |
| Modified | Medium (6.1) | 0.26% | — | Oracle Financial Services Revenue Management AND Billing | 7/16/2024 | 6/17/2026 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 6.0.0.0.0 and 6.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analyzed | High (8.1) | 0.54% | — | Angeljudesuarez Billing System | 7/9/2024 | 6/17/2026 | SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modified | Critical (9.8) | 0.73% | — | Itsourcecode Billing System | 6/13/2024 | 6/17/2026 | A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter. | |
| Modified | Critical (9.8) | 0.64% | — | Kashipara Billing Software | 1/13/2024 | 6/17/2026 | A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modified | Critical (9.8) | 0.57% | — | Kashipara Billing Software | 1/13/2024 | 6/17/2026 | A vulnerability has been found in Kashipara Billing Software 1.0 and classified as critical. This vulnerability affects unknown code of the file party_submit.php of the component HTTP POST Request Handler. The manipulation of the argument party_name leads to sql injection. The attack can be initiated remotely. The… | |
| Modified | Critical (9.8) | 0.53% | — | Kashipara Billing Software | 1/13/2024 | 6/17/2026 | A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bill.php of the component HTTP POST Request Handler. The manipulation of the argument itemtypeid leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modified | Critical (9.8) | 0.53% | — | Kashipara Billing Software | 1/13/2024 | 6/17/2026 | A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_delivery_list.php of the component HTTP POST Request Handler. The manipulation of the argument customer_details leads to sql injection. The attack… | |
| Modified | Critical (9.8) | 0.53% | — | Kashipara Billing Software | 1/13/2024 | 6/17/2026 | A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the file buyer_detail_submit.php of the component HTTP POST Request Handler. The manipulation of the argument gstn_no leads to sql injection. The attack can be launched… | |
| Analyzed | Critical (9.8) | 0.75% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.67% | — | Kashipara Billing Software | 1/4/2024 | 6/17/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modified | Critical (9.8) | 0.65% | — | Fabian Water Billing System | 12/25/2023 | 6/17/2026 | A vulnerability classified as critical has been found in code-projects Water Billing System 1.0. This affects an unknown part of the file /addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… |