Vulnerabilities
33 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-46651 | Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2026-22800 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Request Forgery (CSRF) vulnerability exists in an administrative API endpoint responsible for terminating all active video conferences on a single server. The affected endpoint performs a destructive action but is exposed via an HTTP GET request. Although proper authorization checks are enforced and the endpoint cannot be triggered cross-site, the use of GET allows the action to be implicitly invoked through same-site content (e.g. embedded resources rendered within the application). As a result, an authenticated administrator who views crafted content within the application may unknowingly trigger the endpoint, causing all active video conferences on the server to be terminated without explicit intent or confirmation. This vulnerability is fixed in 4.10.0. NVD description · AI analysis pending | 4.5 | <1% |
| — | ||
| CVE-2025-15138 | A flaw has been found in prasathmani TinyFileManager up to 2.6. A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2025-62523 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in the Access-Control-Allow-Origin response header without proper validation or a whitelist, while Access-Control-Allow-Credentials is set to true. This behavior could allow a malicious website on a different origin to send requests (including credentials) to the PILOS API. This may enable exfiltration or actions using the victim’s credentials if the server accepts those cross-origin requests as authenticated. Laravel’s session handling applies additional origin checks such that cross-origin requests are not authenticated by default. Because of these session-origin protections, and in the absence of any other unknown vulnerabilities that would bypass Laravel’s origin/session checks, this reflected-Origin CORS misconfiguration is not believed to be exploitable in typical PILOS deployments. This vulnerability has been patched in PILOS in v4.8.0 NVD description · AI analysis pending | 6.3 group max | <1% |
| — | ||
| CVE-2025-44998 | A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScri A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-40916 +1 in the same advisory: …40490 | Tiny File Manager v2.4.7 and below is vulnerable to session fixation. Tiny File Manager v2.4.7 and below is vulnerable to session fixation. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-47107 | PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to PILOS users when so that it points to the attackers server thereby disclosing the password reset token if/when the link is followed. This only affects local user accounts and requires the password reset option to be enabled. This issue has been patched in version 2.3.0. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-44239 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jobin Jose WWM Social Share On Image Hover plugin <= 2.2 versions. Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jobin Jose WWM Social Share On Image Hover plugin <= 2.2 versions. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2023-37468 | Feedbacksystem is a personalized feedback system for students using artificial intelligence. Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LDAP login are stored in clear text in the database. The LDAP users password is passed unencrypted in the LoginController.scala and stored in the database when logging in for the first time. Users using only local login or the cas login are not affected. This issue has been patched in version 1.19.2. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-27485 | thmmniii/fbs-core is an open source feedback system for students. thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to associate the subresults with a specific user. This bug was fixed in commit `f1ae67d8bb2`and released with version 1.5.3. Users are advised to upgrade. There are no known workarounds for this issue. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2021-41943 | Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name field. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-45476 | Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2022-31567 +1 in the same advisory: …31566 | The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 group max | 1% | PoC |
| — | |
| CVE-2022-1000 | Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2021-45010 | A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid use A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution. NVD description · AI analysis pending | 8.8 | 70% | PoC ×4 |
| — | |
| CVE-2021-42951 | A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new, specially crafted Algorithm and subsequently launch remote code execution with their desired result. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2021-40965 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2021-31996 | An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::merge(). NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-25094 | LogRhythm Platform Manager 7.4.9 allows Command Injection. LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges. NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — | |
| CVE-2020-12102 +1 in the same advisory: …12103 | In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope). NVD description · AI analysis pending | 7.7 | 2% |
| — | ||
| CVE-2019-16790 | In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2017-8305 | The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g., glibc) that lacks its own strlcpy. NVD description · AI analysis pending | 9.8 | 1% |
| — |