Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

R3Zk0N

#14469of 53,632
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-30495
9.8
2026-04-05
Wisdom · Pegasus Cms · CVE-2019-25687
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.
PT-2023-16962
8.8
2023-04-10
WordPress · Jetengine · CVE-2023-1406
**Name of the Vulnerable Software and Affected Versions** JetEngine WordPress plugin versions prior to 3.1.3.1 **Description** The issue allows for remote code execution due to the plugin's failure to properly verify that uploaded files are not executable. **Recommendations** For versions prior to 3.1.3.1, update to version 3.1.3.1 or later to resolve the issue.