Vulnerabilities
425 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-23929 | Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain. NVD description · AI analysis pending | 8.5 group max | <1% |
| — | ||
| CVE-2026-46709 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete CVE-2026-45038 fix for control characters still allows code execution when the victim presses Enter. This issue is fixed in version 1.0.234. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2025-14771 | Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. NVD description · AI analysis pending | 7.3 group max | <1% |
| — | ||
| CVE-2026-44723 | Vowpal Wabbit is a machine learning system. Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_gen_and_load.py. The shell interprets the expanded string before invoking Python, allowing an attacker to break out of the quotes and execute arbitrary commands on the runner. The pull_request trigger fires on PRs targeting any branch (branches: ['*']), with no additional access gate. This vulnerability is fixed by the 998e390e80a7e8192d7849b7784bc113dbd190ad commit. NVD description · AI analysis pending | 9.9 | <1% | PoC |
| — | |
| CVE-2026-45035 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or sandboxing. An attacker can craft a malicious link (tabby://run?command=...) and deliver it via a website, email, chat message, or any other medium. When a victim clicks the link, the OS launches Tabby which immediately spawns the specified command as a child process with the user's full privileges. This is a zero-click-after-link-visit RCE vulnerability. This vulnerability is fixed in 1.0.233. NVD description · AI analysis pending | 9.4 group max | <1% | PoC |
| — | |
| CVE-2026-23921 | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL sele A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise. NVD description · AI analysis pending | 8.7 group max | 3% |
| — | ||
| CVE-2026-23925 | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2023-53926 +1 in the same advisory: …53927 | PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information. NVD description · AI analysis pending | 8.7 group max | <1% | PoC |
| — | |
| CVE-2023-53877 | Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database. NVD description · AI analysis pending | 9.3 | <1% | PoC ×2 |
| — | |
| CVE-2025-27232 +1 in the same advisory: …49643 | An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. NVD description · AI analysis pending | 6.8 group max | <1% |
| — | ||
| CVE-2025-49641 | A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems. NVD description · AI analysis pending | 5.1 group max | <1% |
| — | ||
| CVE-2025-10827 | A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-27240 +1 in the same advisory: …27238 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. NVD description · AI analysis pending | 7.5 group max | 1% |
| — | ||
| CVE-2023-51328 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters. PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-51295 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2025-3394 +1 in the same advisory: …3395 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0. NVD description · AI analysis pending | 8.5 group max | <1% |
| — | ||
| CVE-2024-36465 | SQL Injection in Zabbix API via groupBy Parameter Zabbix contains a SQL injection flaw (CWE-89) in include/classes/api/CApiService.php, where the groupBy parameter is passed into SQL queries without proper sanitization. Any low-privilege (regular) Zabbix user with API access can exploit it by sending crafted groupBy values through the API, triggering arbitrary SQL command execution. Successful exploitation gives an attacker high-impact read and write capability against the backend database (CVSS 4.0 rates confidentiality, integrity, and availability impact as High), potentially exposing or modifying monitoring configuration and data. All Zabbix deployments that grant API access to regular users are affected; the provided data does not specify affected version ranges. No public proof-of-concept is known and the flaw is not in CISA KEV, but EPSS assigns a 29.5% probability of exploitation within 30 days (98th percentile), indicating elevated near-term risk. Do: Upgrade Zabbix to the patched release published by the vendor for your branch (the fix corrects SQL handling in include/classes/api/CApiService.php). Until patched, restrict API access to trusted users, limit network exposure of the Zabbix API, and audit which accounts hold API permissions. Check logs for API calls containing unexpected or crafted groupBy parameters as a sign of probing or exploitation. | 8.6 group max | 30% |
| large≈ tens of thousands of internet-reachable Zabbix instances (public scans show tens of thousands of exposed Zabbix frontends/APIs), out of an installed base… | ||
| CVE-2023-51339 +1 in the same advisory: …51337 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a l A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2023-51336 | PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2023-51333 | PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2023-51331 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — |