Vulnerabilities

Summary — last 7 days

New vulnerabilities2,767▼ 5 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)240▲ 207 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)0.55%—Simple Bakery Shop Management System Project Simple Bakery Shop Management System3/12/20236/17/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Bakery Shop Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation of the argument username/password with the input admin' or 1=1 -- leads to sql injection. The…
ModifiedMedium (4.8)0.54%—Simple Bakery Shop Management System Project Simple Bakery Shop Management System6/23/20226/17/2026
Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.
ModifiedMedium (4.9)1.2%—Simple Bakery Shop Management System Project Simple Bakery Shop Management System4/4/20226/17/2026
Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
ModifiedHigh (7.5)1.2%—Simple Bakery Shop Management Project Simple Bakery Shop Management3/2/20226/17/2026
Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.