Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

H4X0Rl33Tx

#18945of 53,639
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-41819
6.1
2025-10-13
Wegia · Wegia · CVE-2025-62358
**Name of the Vulnerable Software and Affected Versions** WeGIA versions prior to 3.5.1 **Description** WeGIA is a web management application designed for institutions, particularly those using the Portuguese language. A Reflected Cross-Site Scripting (XSS) issue exists in the `log` parameter of the 'configuracao geral.php' file. This allows an attacker to inject and execute arbitrary JavaScript code within a victim's browser. The API endpoint involved is 'configuracao geral.php', and the vulnerable parameter is `log`. **Recommendations** Update to version 3.5.1 or later.
PT-2024-21653
8.1
2024-03-20
Frappe · Frappe · CVE-2024-27105
**Name of the Vulnerable Software and Affected Versions** Frappe versions prior to 14.66.3 Frappe versions prior to 15.16.0 **Description** Frappe is a full-stack web application framework. The issue allows file permission to be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. **Recommendations** For versions prior to 14.66.3, update to version 14.66.3 or later to resolve the issue. For versions prior to 15.16.0, update to version 15.16.0 or later to resolve the issue.