Vulnerabilities
Summary — last 7 days
New vulnerabilities2,768▲ 75 vs. last week
Critical / high1,288▼ 205 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
268 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 0.48% | — | Fossbilling | 7/31/2023 | 6/17/2026 | Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5. | |
| Modified | Critical (9.8) | 0.83% | — | Cafe Billing System Project Cafe Billing System | 7/28/2023 | 6/17/2026 | A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modified | Medium (4.8) | 0.43% | — | Fossbilling | 7/10/2023 | 6/17/2026 | Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modified | Medium (6.1) | 0.92% | 💥 Exploit | Fossbilling | 7/6/2023 | 6/17/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4. | |
| Modified | High (8) | 0.53% | — | Fossbilling | 6/30/2023 | 6/17/2026 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3. | |
| Modified | High (8.8) | 0.89% | — | Fossbilling | 6/30/2023 | 6/17/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3. | |
| Modified | Critical (9.8) | 0.92% | — | Fossbilling | 6/30/2023 | 6/17/2026 | SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3. | |
| Modified | Medium (5.4) | 0.51% | — | Fossbilling | 6/23/2023 | 6/17/2026 | Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1. | |
| Modified | High (7.2) | 1.0% | — | Fossbilling | 6/23/2023 | 6/17/2026 | Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1. | |
| Modified | Critical (9.8) | 94% | 💥 Exploit | Magnussolution Magnusbilling | 6/23/2023 | 6/17/2026 | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request. | |
| Modified | High (7.5) | 0.41% | — | Fossbilling | 6/14/2023 | 6/17/2026 | Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0. | |
| Modified | Medium (6.5) | 0.51% | — | Fossbilling | 6/14/2023 | 6/17/2026 | Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | |
| Modified | Medium (5.7) | 0.48% | — | Fossbilling | 6/14/2023 | 6/17/2026 | Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0. | |
| Modified | Medium (5.7) | 0.41% | — | Fossbilling | 6/14/2023 | 6/17/2026 | Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0. | |
| Modified | High (8.8) | 0.82% | — | Oretnom23 Establishment Billing Management System | 5/14/2023 | 6/17/2026 | A vulnerability classified as critical was found in SourceCodester Billing Management System 1.0. This vulnerability affects unknown code of the file editproduct.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Modified | Critical (9.8) | 0.83% | — | Oretnom23 Establishment Billing Management System | 5/9/2023 | 6/17/2026 | A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Parameter Handler. The manipulation of the argument drop_services leads to sql injection. The attack… | |
| Modified | Medium (6.1) | 0.51% | — | Boxbilling | 4/28/2023 | 6/17/2026 | Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form. | |
| Modified | Medium (6.1) | 0.44% | — | Water Billing System Project Water Billing System | 3/27/2023 | 6/17/2026 | SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module. | |
| Modified | Medium (4.4) | 0.21% | — | Oracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Policy | 1/18/2023 | 6/17/2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the… | |
| Modified | Critical (9.8) | 0.83% | — | Billing System Project Project Billing System Project | 11/23/2022 | 6/17/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. | |
| Modified | Critical (9.8) | 0.91% | — | Billing System Project Project Project Billing System Project | 11/22/2022 | 6/17/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. | |
| Modified | Critical (9.8) | 0.91% | — | Billing System Project Billing System | 11/22/2022 | 6/17/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php. | |
| Modified | Critical (9.8) | 0.93% | — | Billing System Project Billing System | 11/22/2022 | 6/17/2026 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. | |
| Modified | High (7.5) | 0.44% | — | Samsung Billing | 11/9/2022 | 6/17/2026 | Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information. | |
| Modified | Medium (4.8) | 0.52% | — | Official Integration FOR Billingo Project Official Integration FOR Billingo | 10/31/2022 | 6/17/2026 | The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks. |