Vulnerabilities
Summary — last 7 days
New vulnerabilities2,686▼ 84 vs. last week
Critical / high1,444▲ 301 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
118 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.1) | 0.47% | — | Sourcecodester Queue Management SystemAI | 8/30/2026 | 8/31/2026 | A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Deferred | Low (3.7) | 0.46% | — | Cakephp QueueAI | 8/27/2026 | 9/9/2026 | CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can… | |
| Analyzed | High (8.1) | 0.36% | — | Oracle Universal Work Queue | 7/21/2026 | 7/30/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.… | |
| Analyzed | Medium (6.6) | 0.38% | — | Oracle Universal Work Queue | 7/21/2026 | 7/30/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Analyzed | High (8.1) | 0.38% | — | Oracle Universal Work Queue | 7/21/2026 | 7/30/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue.… | |
| Analyzed | High (7.5) | 0.33% | — | Oracle Universal Work Queue | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analyzed | High (8.8) | 0.43% | — | Oracle Universal Work Queue | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Universal Work Queue | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Universal Work Queue | 6/17/2026 | 6/18/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Analyzed | Critical (9.9) | 0.43% | — | Oracle Universal Work Queue | 5/28/2026 | 7/21/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Deferred | Medium (5.1) | 0.24% | — | Queue Management SystemAI | 5/16/2026 | 9/29/2026 | Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing… | |
| Deferred | High (7.7) | 0.60% | — | Craftcms CommerceAIYiisoft Yii2-queueAIGuzzlephp GuzzleAI | 4/13/2026 | 6/17/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitation chain. The… | |
| Deferred | Medium (5.5) | 0.47% | — | Sourcecodester Patients Waiting Area Queue Management SystemAI | 3/24/2026 | 6/17/2026 | A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToken of the file /php/api_patient_checkin.php of the component Patient Check-In Module. Executing a manipulation can lead to improper authorization. It is possible to launch… | |
| Analyzed | Medium (5.2) | 0.21% | — | Cps-it Mailqueue | 3/17/2026 | 6/17/2026 | The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath']. | |
| Analyzed | Medium (5.5) | 0.60% | — | Pamzey Patients Waiting Area Queue Management System | 3/9/2026 | 6/17/2026 | A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. | |
| Analyzed | Low (2.1) | 0.48% | — | Pamzey Patients Waiting Area Queue Management System | 3/8/2026 | 6/17/2026 | A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of the argument patient_id causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available… | |
| Analyzed | Low (2) | 0.35% | — | Pamzey Patients Waiting Area Queue Management System | 2/25/2026 | 6/17/2026 | A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The attack is possible to be carried out… | |
| Analyzed | Low (1.9) | 0.37% | — | Pamzey Patients Waiting Area Queue Management System | 2/25/2026 | 6/17/2026 | A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected is an unknown function of the file /patient-search.php. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be executed remotely. The exploit is now… | |
| Analyzed | Low (2.1) | 0.32% | — | Pamzey Patients Waiting Area Queue Management System | 2/8/2026 | 6/17/2026 | A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of the file /registration.php of the component Patient Registration Module. The manipulation of the argument First Name leads to cross site scripting. Remote exploitation of… | |
| Analyzed | Low (2.1) | 0.37% | — | Pamzey Patients Waiting Area Queue Management System | 2/8/2026 | 6/17/2026 | A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /checkin.php. This manipulation of the argument patient_id causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analyzed | Low (2.1) | 0.37% | — | Pamzey Patients Waiting Area Queue Management System | 2/8/2026 | 6/17/2026 | A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /appointments.php. The manipulation of the argument patient_id results in cross site scripting. It is possible to launch the attack… | |
| Analyzed | Medium (5.3) | 0.24% | — | Pamzey Patients Waiting Area Queue Management System | 1/19/2026 | 6/17/2026 | A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown code. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. | |
| Analyzed | Low (2) | 0.27% | — | Pamzey Patients Waiting Area Queue Management System | 1/19/2026 | 6/17/2026 | A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analyzed | Low (2) | 0.21% | — | Pamzey Patients Waiting Area Queue Management System | 1/19/2026 | 6/17/2026 | A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be… | |
| Modified | Critical (9.8) | 0.41% | — | Pamzey Patients Waiting Area Queue Management System | 12/8/2025 | 6/17/2026 | SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter. |