Vulnerabilities
26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-40162 | Bugsink is a self-hosted error tracking tool. Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the Bugsink process. This vulnerability is fixed in 2.1.1. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2026-27614 | Bugsink is a self-hosted error tracking tool. Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments returns more lines than it was given (a known upstream quirk that triggers with Ruby heredoc-style input), `_pygmentize_lines()` in `theme/templatetags/issues.py:75-77` falls back to returning the raw input lines. `mark_safe()` at line 111-113 is then applied unconditionally - including to those unsanitized raw lines. Since DSN endpoints are public by Sentry protocol, no account is needed to inject. The payload sits in the database until an admin looks at the event. Successful exploitation requires that the attacker to be able to submit events to the project (i.e. knows the DSN or can access a client that uses it), the Bugsink ingest endpoint is reachable to the attacker, and an administrator explicitly views the crafted event in the UI. Under those conditions, the attacker can execute JavaScript in the administrator’s browser and act with that user’s privileges within Bugsink. Version 2.0.13 fixes the vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-1044 | Critical Authentication Bypass in Logsign Unified SecOps Platform CVE-2025-1044 is a critical authentication bypass (CWE-287) in the web service of Logsign Unified SecOps Platform, the vendor's SIEM/SOAR offering. The web service listens on TCP port 443 by default, and because its authentication algorithm is improperly implemented, any remote attacker who can reach the service can bypass authentication without credentials. Successful exploitation grants unauthenticated access to the platform's web console, exposing stored security logs, alerts and configuration, and the 9.8 CVSS score reflects potentially high impact to confidentiality, integrity and availability. Any organization running Logsign Unified SecOps Platform is affected, with the greatest risk where the web interface is reachable from the internet or shared networks, a common pattern for analyst remote access and MSSP-hosted deployments. The flaw is not yet in CISA KEV and no public PoC is known, but EPSS assigns a 75.3% probability of exploitation within 30 days (99th percentile), so near-term exploitation attempts should be treated as likely. Do: Check the Logsign security advisory (referenced as ZDI-CAN-25336) for the patched release and upgrade promptly, since no fixed version numbers are included in the available data. Until patched, restrict TCP 443 access to the platform's web service to trusted management networks or VPN, confirm whether your instance is internet-facing, and review access and audit logs for signs of unauthenticated logins or configuration changes. | 9.8 | 75% |
| nicheon the order of a few thousand deployments, with an unknown smaller subset internet-exposed on TCP 443 | ||
| CVE-2024-5716 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password reset mechanism. The issue results from the lack of restriction of excessive authentication attempts. An attacker can leverage this vulnerability to reset a user's password and bypass authentication on the system. Was ZDI-CAN-24164. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2024-7603 | Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete directories in the context of root. Was ZDI-CAN-25028. NVD description · AI analysis pending | 8.1 group max | 2% |
| — | ||
| CVE-2024-7564 | Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the get_response_json_result endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-24680. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2017-20017 | A vulnerability, which was classified as critical, has been found in The Next Generation of Genealogy Sitebuilding up to 11.1.0. A vulnerability, which was classified as critical, has been found in The Next Generation of Genealogy Sitebuilding up to 11.1.0. This issue affects some unknown processing of the file /timeline2.php. The manipulation of the argument primaryID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.1.1 is able to address this issue. It is recommended to upgrade the affected component. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2019-7639 | An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins succeed with a valid username and an incorrect password, even though a failure entry is recorded in the /var/log/messages file. NVD description · AI analysis pending | 8.1 | 1% | PoC |
| — | |
| CVE-2018-13540 | The mintToken function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow that allows the owner of the contract to set the b The mintToken function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-13233 | The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2017-2213 | Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. 1.0.2 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-2212 | Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-2211 +1 in the same advisory: …2210 | Untrusted search path vulnerability in PatchJGD (Hyoko) (PatchJGDh101.EXE) ver. Untrusted search path vulnerability in PatchJGD (Hyoko) (PatchJGDh101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2016-4814 | Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows rem Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows remote attackers to read arbitrary files via unspecified vectors. NVD description · AI analysis pending | 7.5 | 2% |
| — |