Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ling12138-Sg

#17405of 55,077
15.9Total CVSS
Vulnerabilities · 2
High
2
PT-2026-56247
8.7
2026-07-07
Dataease · Dataease · CVE-2026-53730
**Name of the Vulnerable Software and Affected Versions** DataEase versions prior to 2.10.24 **Description** The '/de2api/datasetData/previewSql' endpoint lacks the mandatory `@DePermit` permission validation annotation. This allows any authenticated user to set the `datasourceId` variable to -1, granting unauthorized access to the built-in engine database to execute arbitrary SQL statements and read sensitive core data. **Recommendations** Update to version 2.10.24. Restrict access to the '/de2api/datasetData/previewSql' endpoint as a temporary mitigation.
PT-2026-44901
7.2
2026-05-29
Emlog Pro · Emlog Pro · CVE-2026-39276
**Name of the Vulnerable Software and Affected Versions** Emlog Pro version 2.6.9 **Description** The template upload feature contains a path traversal issue, which occurs when an application uses user-supplied input to construct a pathname that is then used in a file operation. This allows authenticated administrators to execute arbitrary PHP code by uploading a malicious ZIP archive containing directory traversal sequences in filenames. This process enables the overwriting of default template files or the direct inclusion of malicious code files within the current template. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.