Vulnerabilities
23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59106 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-3733 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).Th Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2023-0737 | wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/del wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-49327 | Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web Server.This Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web Server.This issue affects Woostagram Connect: from n/a through <= 1.0.2. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-4455 +1 in the same advisory: …4454 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2023-3566 | A vulnerability was found in wallabag 2.5.4. A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233359. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 6.5 | 1% | PoC ×2 |
| — | |
| CVE-2023-37122 | A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected int A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-0734 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2023-0735 +1 in the same advisory: …0736 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4. Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2023-0609 +1 in the same advisory: …0610 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2023-22333 | Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-25842 | All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially cr All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2021-37786 | Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0 and below affected, patch in progress and COVID Certificate Check App IOS 2.2.0 and below affected, patch in progress. A denial of service (physically proximate) could be caused by scanning a crafted QR code. NVD description · AI analysis pending | 4.6 | <1% | PoC |
| — | |
| CVE-2019-8421 | upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter. upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2018-19560 | BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-19104 | In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges. In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-18258 +1 in the same advisory: …18257 | An issue was discovered in BageCMS 3.1.3. An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2018-11352 | The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions. NVD description · AI analysis pending | 4.0 | <1% | PoC |
| — | |
| CVE-2018-14582 | index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — |