Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jasmin Landry

#16681of 53,632
16.1Total CVSS
Vulnerabilities · 2
High
2
PT-2025-10114
7.5
2025-03-07
Ibm · Ibm Aspera Shares · CVE-2025-0162
**Name of the Vulnerable Software and Affected Versions** IBM Aspera Shares versions 1.9.9 through 1.10.0 PL7 **Description** The issue allows a remote authenticated attacker to expose sensitive information or consume memory resources through an XML external entity injection (XXE) attack when processing XML data. **Recommendations** For versions 1.9.9 through 1.10.0 PL7, update to a version that includes a fix for the XML external entity injection issue to prevent XXE attacks.
PT-2022-9422
8.6
2022-01-21
Isomorphic Git · @Isomorphic-Git/Cors-Proxy · CVE-2021-23664
**Name of the Vulnerable Software and Affected Versions** @isomorphic-git/cors-proxy versions prior to 2.7.1 **Description** The issue is related to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js. This allows for potential exploitation. **Recommendations** For versions prior to 2.7.1, update to version 2.7.1 or later to resolve the issue. As a temporary workaround, consider disabling the redirection action in middleware.js until a patch is available. Restrict access to the middleware.js module to minimize the risk of exploitation.