CVE Severity Distribution (Last 30 Days)
Found 5 CVEs in the last 30 days.
CVE-2026-3055
CRITICAL
CVSS: 9.8
EPSS: 87.2%
VulnCheck KEV
PoC Available
CWE-125
T1005
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Published: 2026-03-23
CVE-2026-30556
MEDIUM
CVSS: 6.1
EPSS: 0.3%
CWE-79
T1189
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30
CVE-2026-30557
MEDIUM
CVSS: 6.1
EPSS: 0.3%
CWE-79
T1189
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_category.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30
CVE-2026-30558
MEDIUM
CVSS: 6.1
EPSS: 0.3%
CWE-79
T1189
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30
CVE-2026-30559
MEDIUM
CVSS: 6.1
EPSS: 0.3%
CWE-79
T1189
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30