Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

268 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.5)0.67%—Oracle Communications Billing AND Revenue Management10/18/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to…
ModifiedHigh (7.2)1.2%—Billing System Project Billing System10/18/20226/17/2026
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModifiedHigh (7.2)44%💥 ExploitBoxbilling10/17/20226/17/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
ModifiedHigh (7.2)0.78%—Billing System Project Billing System10/17/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.
ModifiedHigh (7.1)0.41%—WOO Billingo Plus Project WOO Billingo PlusIntegration FOR Billingo & Gravity Forms Project Integration FOR Billingo & Gravity FormsIntegration FOR Szamlazz.hu & Gravity Forms Project Integration FOR Szamlazz.hu & Gravity Forms10/10/20226/17/2026
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above…
ModifiedHigh (7.2)0.86%—Billing System Project Project Billing System Project9/30/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.
ModifiedHigh (7.2)0.86%—Billing System Project Project Billing System Project9/30/20226/17/2026
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.
ModifiedHigh (7.2)1.7%—Billing System Project Project Billing System Project9/30/20226/17/2026
Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.
ModifiedCritical (9.8)0.63%—Automated Beer Parlour Billing System Project Automated Beer Parlour Billing System8/12/20226/17/2026
A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this…
ModifiedMedium (5.9)0.52%—Oracle Financial Services Revenue Management AND Billing7/19/20226/17/2026
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 2.9.0.0.0, 2.9.0.1.0, 3.0.0.0.0-3.2.0.0.0 and 4.0.0.0.0. Difficult to exploit vulnerability allows low privileged…
ModifiedMedium (5.3)1.0%—Oracle Communications Billing AND Revenue Management7/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModifiedMedium (6.5)0.78%—Oracle Communications Billing AND Revenue Management7/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModifiedMedium (5.4)0.46%—Oracle Communications Billing AND Revenue Management7/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModifiedHigh (8.1)1.4%—Oracle Communications Billing AND Revenue Management7/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to…
ModifiedMedium (5.4)0.50%—Water Billing System Project Water Billing System5/24/20226/17/2026
Water-billing-management-system v1.0 is affected by: Cross Site Scripting (XSS) via /wbms/classes/Users.php?f=save, firstname.
ModifiedCritical (9.8)1.1%—Water Billing System Project Water Billing System5/24/20226/17/2026
Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id
ModifiedCritical (10)2.1%—Oracle Communications Billing AND Revenue Management4/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to…
ModifiedHigh (8.5)1.2%—Oracle Communications Billing AND Revenue Management4/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to…
ModifiedHigh (8.3)1.3%—Oracle Communications Billing AND Revenue Management4/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle…
ModifiedHigh (7.5)1.0%—Oracle Communications Billing AND Revenue Management4/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to…
ModifiedHigh (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+323/11/20226/17/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModifiedMedium (6.1)1.0%—THE Electric Billing Management System Project THE Electric Billing Management System1/24/20226/17/2026
Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute arbitrary code via the about page.
ModifiedCritical (9.9)1.2%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModifiedCritical (10)2.4%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Webservices Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModifiedCritical (10)1.9%—Oracle Communications Billing AND Revenue Management1/19/20226/17/2026
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…