CVE-2026-10255
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sel
CVSS
5.3
Medio
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-266 · CWE-284
0.3%EPSS · 30 días0.3%
2026-08-142026-09-10
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-621068.8 ALT—
———Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.5hCVE-2026-621028.8 ALT—
———Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.5hCVE-2026-83037.8 ALT—
———Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation.
This issue affects Pardus-software: before 1.0.5.9hCVE-2026-47839——
——0A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.11hCVE-2026-868126.5 MED—
——0The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.9hCVE-2026-819418.8 ALT—
——0IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.8h