|
631
|
6.5 |
MEDIUM
Network
|
elastic
|
kibana
|
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containin…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-49094
|
2026-06-1 22:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
6.5 |
MEDIUM
Network
|
elastic
|
kibana
|
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent po…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-49095
|
2026-06-1 22:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
7.8 |
HIGH
Local
|
canonical
|
multipass
|
An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd da…
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-49237
|
2026-06-1 22:27 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
8.4 |
HIGH
Local
|
canonical
|
multipass
|
An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment …
Update
|
CWE-22
Path Traversal
|
CVE-2026-49238
|
2026-06-1 22:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10244
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
3.5 |
LOW
Network
|
-
|
-
|
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipul…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10245
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/mai…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10246
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The ma…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-10247
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplie…
New
|
CWE-74 CWE-1236
Injection Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-10248
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10249
|
2026-06-1 22:14 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|