Total
54 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-41973 | 2026-06-09 | N/A | 5.9 MEDIUM | ||
| Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-11465 | 2026-06-08 | 2.1 LOW | 3.1 LOW | ||
| A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance. | |||||
| CVE-2026-8738 | 2026-05-18 | 6.4 MEDIUM | 6.5 MEDIUM | ||
| A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component Trade Payment Flow. The manipulation leads to business logic errors. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-1322 | 1 Gitlab | 1 Gitlab | 2026-05-16 | N/A | 6.8 MEDIUM |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to improper authorization. | |||||
| CVE-2026-41968 | 2026-05-15 | N/A | 5.9 MEDIUM | ||
| Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-41966 | 2026-05-15 | N/A | 5.6 MEDIUM | ||
| Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |||||
| CVE-2026-41961 | 2026-05-15 | N/A | 5.9 MEDIUM | ||
| Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-41967 | 2026-05-15 | N/A | 5.9 MEDIUM | ||
| Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-41965 | 2026-05-15 | N/A | 5.6 MEDIUM | ||
| Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-41971 | 2026-05-15 | N/A | 5.5 MEDIUM | ||
| Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |||||
| CVE-2026-1599 | 1 Bdtask | 1 Bhojon | 2026-04-29 | 4.0 MEDIUM | 4.3 MEDIUM |
| A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the argument orggrandTotal/vat/service_charge/grandtotal can lead to business logic errors. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-5812 | 2026-04-29 | 5.5 MEDIUM | 5.4 MEDIUM | ||
| A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performing a manipulation of the argument txtqty results in business logic errors. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. | |||||
| CVE-2025-8991 | 1 Linlinjava | 1 Litemall | 2026-04-29 | 4.0 MEDIUM | 4.3 MEDIUM |
| A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_freight_min leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2026-5811 | 2026-04-29 | 5.5 MEDIUM | 5.4 MEDIUM | ||
| A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The attack may be performed from remote. The exploit is publicly available and might be used. | |||||
| CVE-2026-1600 | 1 Bdtask | 1 Bhojon | 2026-04-29 | 4.0 MEDIUM | 4.3 MEDIUM |
| A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice leads to business logic errors. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2025-13239 | 1 Bdtask | 1 Isshue | 2026-04-29 | 4.0 MEDIUM | 4.3 MEDIUM |
| A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument order_total_amount/cart_total_amount leads to enforcement of behavioral workflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-1274 | 1 Ibm | 1 Guardium Data Protection | 2026-04-27 | N/A | 4.9 MEDIUM |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel. | |||||
| CVE-2026-4547 | 2026-04-24 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely. | |||||
| CVE-2024-1682 | 2026-04-15 | N/A | 4.3 MEDIUM | ||
| An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an external party. The use of this unclaimed S3 bucket could lead to data integrity issues, data leakage, availability problems, loss of trustworthiness, and potential further attacks if the bucket is used to host malicious content or as a pivot point for further attacks. | |||||
| CVE-2025-14559 | 2026-04-15 | N/A | 6.5 MEDIUM | ||
| A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes the token exchange flow. | |||||
