Vulnerabilities

Summary — last 7 days

New vulnerabilities2,768▲ 75 vs. last week
Critical / high1,288▼ 205 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

268 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)0.48%—Fossbilling7/31/20236/17/2026
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
ModifiedCritical (9.8)0.83%—Cafe Billing System Project Cafe Billing System7/28/20236/17/2026
A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been…
ModifiedMedium (4.8)0.43%—Fossbilling7/10/20236/17/2026
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModifiedMedium (6.1)0.92%💥 ExploitFossbilling7/6/20236/17/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.
ModifiedHigh (8)0.53%—Fossbilling6/30/20236/17/2026
Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.
ModifiedHigh (8.8)0.89%—Fossbilling6/30/20236/17/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
ModifiedCritical (9.8)0.92%—Fossbilling6/30/20236/17/2026
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
ModifiedMedium (5.4)0.51%—Fossbilling6/23/20236/17/2026
Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.
ModifiedHigh (7.2)1.0%—Fossbilling6/23/20236/17/2026
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.
ModifiedCritical (9.8)94%💥 ExploitMagnussolution Magnusbilling6/23/20236/17/2026
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
ModifiedHigh (7.5)0.41%—Fossbilling6/14/20236/17/2026
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.
ModifiedMedium (6.5)0.51%—Fossbilling6/14/20236/17/2026
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
ModifiedMedium (5.7)0.48%—Fossbilling6/14/20236/17/2026
Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.
ModifiedMedium (5.7)0.41%—Fossbilling6/14/20236/17/2026
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
ModifiedHigh (8.8)0.82%—Oretnom23 Establishment Billing Management System5/14/20236/17/2026
A vulnerability classified as critical was found in SourceCodester Billing Management System 1.0. This vulnerability affects unknown code of the file editproduct.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has…
ModifiedCritical (9.8)0.83%—Oretnom23 Establishment Billing Management System5/9/20236/17/2026
A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Parameter Handler. The manipulation of the argument drop_services leads to sql injection. The attack…
ModifiedMedium (6.1)0.51%—Boxbilling4/28/20236/17/2026
Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form.
ModifiedMedium (6.1)0.44%—Water Billing System Project Water Billing System3/27/20236/17/2026
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module.
ModifiedMedium (4.4)0.21%—Oracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Policy1/18/20236/17/2026
Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the…
ModifiedCritical (9.8)0.83%—Billing System Project Project Billing System Project11/23/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
ModifiedCritical (9.8)0.91%—Billing System Project Project Project Billing System Project11/22/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
ModifiedCritical (9.8)0.91%—Billing System Project Billing System11/22/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
ModifiedCritical (9.8)0.93%—Billing System Project Billing System11/22/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
ModifiedHigh (7.5)0.44%—Samsung Billing11/9/20226/17/2026
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
ModifiedMedium (4.8)0.52%—Official Integration FOR Billingo Project Official Integration FOR Billingo10/31/20226/17/2026
The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.
Orbitaley — Vulnerabilities