Known Vulnerabilities for ERP Online by Devs Palace
Listed below are 10 of the newest known vulnerabilities associated with "ERP Online" by "Devs Palace".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43404 json | In the Linux kernel, the following vulnerability has been resolved: mm: Fix a hmm_range_fault() livelock / starvation proble... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-43274 json | In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_... | Not Provided | 2026-05-06 | 2026-05-08 |
| CVE-2026-41459 json | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated a... | Not Provided | 2026-04-22 | 2026-04-24 |
| CVE-2026-41213 json | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-i... | Not Provided | 2026-04-23 | 2026-04-25 |
| CVE-2026-40097 json | Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.3... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-39985 json | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-mana... | Not Provided | 2026-04-09 | 2026-04-10 |
| CVE-2026-38940 json | Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via t... | Not Provided | 2026-04-30 | 2026-04-30 |
| CVE-2026-37597 json | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attenda... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2026-37596 json | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attenda... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2026-37595 json | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attenda... | Not Provided | 2026-04-14 | 2026-04-14 |