Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bruno López

#14364of 53,633
18.7Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2025-20380
8.7
2025-05-08
Unknown · Wp Page Builder · CVE-2024-6648
**Name of the Vulnerable Software and Affected Versions** AP Page Builder versions prior to 4.0.0 **Description** The issue is an Absolute Path Traversal vulnerability that could allow an unauthenticated remote user to modify the `product item path` within the `config` JSON file, allowing them to read any file on the system. **Recommendations** For AP Page Builder versions prior to 4.0.0, update to version 4.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the `config` JSON file to prevent modification of the `product item path`.
PT-2022-2603
10
2022-05-18
Vmware · Identity Manager · CVE-2022-22972
**Name of the Vulnerable Software and Affected Versions** VMware Workspace ONE Access, Identity Manager and vRealize Automation (affected versions not specified) **Description** The issue is related to an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. This vulnerability allows an attacker to enter the system as any known local user. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.