Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

摆烂人

#13720of 53,635
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2024-14060
9.8
2024-01-04
Jizhicms · Jizhicms · CVE-2023-51154
**Name of the Vulnerable Software and Affected Versions** Jizhicms version 2.5 **Description** The issue is related to an arbitrary file download vulnerability. It affects the component `/admin/c/PluginsController.php`. **Recommendations** For Jizhicms version 2.5, consider restricting access to the `/admin/c/PluginsController.php` component until a patch is available. As a temporary workaround, avoid using the vulnerable component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-14303
9.8
2024-01-04
Tenda · Tenda Ax3 · CVE-2023-51812
**Name of the Vulnerable Software and Affected Versions** Tenda AX3 version 16.03.12.11 **Description** A remote code execution issue was discovered via the `list` parameter at the "/goform/SetNetControlList" API endpoint. **Recommendations** For Tenda AX3 version 16.03.12.11, as a temporary workaround, consider restricting access to the "/goform/SetNetControlList" API endpoint until a patch is available. Avoid using the `list` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.