Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

T4Rnrookie

#13748of 53,632
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2025-37721
9.8
2025-09-15
Amazon · Amazon Redshift · CVE-2025-58748
**Name of the Vulnerable Software and Affected Versions** Dataease versions prior to 2.10.13 **Description** Dataease is an open source data analytics and visualization platform. The H2 data source implementation (H2.java) lacks validation to ensure that a provided JDBC URL begins with `jdbc:h2`. This allows a crafted JDBC configuration to substitute the Amazon Redshift driver and utilize the `socketFactory` and `socketFactoryArg` parameters to invoke `org.springframework.context.support.FileSystemXmlApplicationContext` or `ClassPathXmlApplicationContext` with a remote XML resource controlled by an attacker, potentially leading to remote code execution. **Recommendations** Update to Dataease version 2.10.13 or later.
PT-2022-25610
9.8
2022-10-18
Phpok · Phpok · CVE-2022-40889
**Name of the Vulnerable Software and Affected Versions** Phpok version 6.1 **Description** The issue is related to a deserialization vulnerability. It affects the framework/phpok call.php file. **Recommendations** For Phpok version 6.1, consider restricting access to the framework/phpok call.php file until a patch is available. As a temporary workaround, avoid using deserialization functions in the affected file to minimize the risk of exploitation.