CVE-2026-9412
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpo
CVSS
6.3
Medio
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Publicado: 25 may 2026 · Última mod.: 23 jul 2026 · CWE-266 · CWE-284
0.2%EPSS · 30 días0.2%
2026-07-152026-08-12
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Multiple endpoints are affected.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-595058.6 ALT—
——0CWE-284: Improper Access Control3hCVE-2026-595018.2 ALT—
——0CWE-284: Improper Access Control3hCVE-2026-133677.8 ALT—
——0IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.16hCVE-2026-599177.8 ALT—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.8hCVE-2026-599147.8 ALT—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.8hCVE-2025-94863.3 BAJ—
——0GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.17h