Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

D47Sec

#19068of 53,622
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-33273
6.8
2025-08-13
Apache · Apache Superset · CVE-2025-55674
Name of the Vulnerable Software and Affected Versions: Apache Superset versions prior to 5.0.0 Description: A bypass of the `DISALLOWED SQL FUNCTIONS` security feature allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, potentially leading to the disclosure of sensitive database information, such as the software version. Recommendations: Upgrade to version 5.0.0.
PT-2023-16397
7.2
2023-02-01
Unknown · Projectsend · CVE-2023-0607
**Name of the Vulnerable Software and Affected Versions** projectsend/projectsend versions prior to r1606 **Description** The issue is related to Cross-site Scripting (XSS) - Stored, which affects the GitHub repository projectsend/projectsend. This type of attack involves injecting malicious scripts into a website, allowing an attacker to steal user data or take control of the user's session. **Recommendations** For versions prior to r1606, update to version r1606 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.