Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

R3Zk0N

#14524de 53,635
18.6CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2026-30495
9.8
2026-04-05
Wisdom · Pegasus Cms · CVE-2019-25687
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.
PT-2023-16962
8.8
2023-04-10
WordPress · Jetengine · CVE-2023-1406
**Name of the Vulnerable Software and Affected Versions** JetEngine WordPress plugin versions prior to 3.1.3.1 **Description** The issue allows for remote code execution due to the plugin's failure to properly verify that uploaded files are not executable. **Recommendations** For versions prior to 3.1.3.1, update to version 3.1.3.1 or later to resolve the issue.