Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

M1Tz

#18459of 53,630
14.6Total CVSS
Vulnerabilities · 2
High
2
PT-2025-23755
7.1
2025-06-04
Samsung · Samsung Internet · CVE-2025-20994
**Name of the Vulnerable Software and Affected Versions** Samsung Internet versions prior to 28.0.0.59 **Description** The issue arises from improper handling of insufficient permission in SyncClientProvider, allowing local attackers to access and modify arbitrary files. This affects Samsung Internet installed on non-Samsung devices. **Recommendations** For versions prior to 28.0.0.59, update to version 28.0.0.59 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
PT-2024-18821
7.5
2024-06-13
WordPress · Download Manager · CVE-2024-2098
**Name of the Vulnerable Software and Affected Versions** Download Manager plugin for WordPress versions up to, and including, 3.2.89 **Description** The issue arises from an improper authorization check on the `protectMediaLibrary` function, allowing unauthenticated attackers to access password-protected files. This enables unauthorized data access, specifically permitting attackers to download files that should be restricted. **Recommendations** For versions up to, and including, 3.2.89, update to a version higher than 3.2.89 to resolve the issue. As a temporary workaround, consider disabling the `protectMediaLibrary` function until a patch is available.