Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Marcin Nowak

#22148of 53,632
10.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-52047
5.8
2025-12-18
Mkscripts · Mkscripts · CVE-2025-54743
**Name of the Vulnerable Software and Affected Versions** mkscripts Download After Email versions through 2.1.6 **Description** The software contains a missing authorization issue in the download-after-email functionality. This allows exploitation due to incorrectly configured access control security levels. **Recommendations** Versions prior to 2.1.6 should be updated.
PT-2025-20286
4.5
2025-05-07
Unknown · Dropbear Ssh · CVE-2025-47203
**Name of the Vulnerable Software and Affected Versions** Dropbear SSH versions prior to 2025.88 **Description** The issue allows command injection via an untrusted hostname argument, because a shell is used. This occurs when the `dbclient` in Dropbear SSH is used with an untrusted hostname. **Recommendations** For versions prior to 2025.88, update to version 2025.88 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all hostname arguments to prevent command injection. Restrict access to the `dbclient` until the issue is resolved.