Vulnerabilities

Summary — last 7 days

New vulnerabilities2,686▼ 84 vs. last week
Critical / high1,444▲ 301 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

118 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredLow (2.1)0.47%—Sourcecodester Queue Management SystemAI8/30/20268/31/2026
A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used.
DeferredLow (3.7)0.46%—Cakephp QueueAI8/27/20269/9/2026
CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can…
AnalyzedHigh (8.1)0.36%—Oracle Universal Work Queue7/21/20267/30/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.…
AnalyzedMedium (6.6)0.38%—Oracle Universal Work Queue7/21/20267/30/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
AnalyzedHigh (8.1)0.38%—Oracle Universal Work Queue7/21/20267/30/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue.…
AnalyzedHigh (7.5)0.33%—Oracle Universal Work Queue6/17/20266/18/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalyzedHigh (8.8)0.43%—Oracle Universal Work Queue6/17/20266/18/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal…
AnalyzedCritical (9.9)0.43%—Oracle Universal Work Queue6/17/20266/18/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal…
AnalyzedCritical (9.9)0.43%—Oracle Universal Work Queue6/17/20266/18/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal…
AnalyzedCritical (9.9)0.43%—Oracle Universal Work Queue5/28/20267/21/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal…
DeferredMedium (5.1)0.24%—Queue Management SystemAI5/16/20269/29/2026
Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing…
DeferredHigh (7.7)0.60%—Craftcms CommerceAIYiisoft Yii2-queueAIGuzzlephp GuzzleAI4/13/20266/17/2026
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitation chain. The…
DeferredMedium (5.5)0.47%—Sourcecodester Patients Waiting Area Queue Management SystemAI3/24/20266/17/2026
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToken of the file /php/api_patient_checkin.php of the component Patient Check-In Module. Executing a manipulation can lead to improper authorization. It is possible to launch…
AnalyzedMedium (5.2)0.21%—Cps-it Mailqueue3/17/20266/17/2026
The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].
AnalyzedMedium (5.5)0.60%—Pamzey Patients Waiting Area Queue Management System3/9/20266/17/2026
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used.
AnalyzedLow (2.1)0.48%—Pamzey Patients Waiting Area Queue Management System3/8/20266/17/2026
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of the argument patient_id causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available…
AnalyzedLow (2)0.35%—Pamzey Patients Waiting Area Queue Management System2/25/20266/17/2026
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The attack is possible to be carried out…
AnalyzedLow (1.9)0.37%—Pamzey Patients Waiting Area Queue Management System2/25/20266/17/2026
A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected is an unknown function of the file /patient-search.php. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be executed remotely. The exploit is now…
AnalyzedLow (2.1)0.32%—Pamzey Patients Waiting Area Queue Management System2/8/20266/17/2026
A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of the file /registration.php of the component Patient Registration Module. The manipulation of the argument First Name leads to cross site scripting. Remote exploitation of…
AnalyzedLow (2.1)0.37%—Pamzey Patients Waiting Area Queue Management System2/8/20266/17/2026
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /checkin.php. This manipulation of the argument patient_id causes cross site scripting. The attack can be initiated remotely. The exploit has been…
AnalyzedLow (2.1)0.37%—Pamzey Patients Waiting Area Queue Management System2/8/20266/17/2026
A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /appointments.php. The manipulation of the argument patient_id results in cross site scripting. It is possible to launch the attack…
AnalyzedMedium (5.3)0.24%—Pamzey Patients Waiting Area Queue Management System1/19/20266/17/2026
A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown code. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely.
AnalyzedLow (2)0.27%—Pamzey Patients Waiting Area Queue Management System1/19/20266/17/2026
A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The…
AnalyzedLow (2)0.21%—Pamzey Patients Waiting Area Queue Management System1/19/20266/17/2026
A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be…
ModifiedCritical (9.8)0.41%—Pamzey Patients Waiting Area Queue Management System12/8/20256/17/2026
SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter.