Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vini_Castro

#20159of 53,624
12.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-35161
4.0
2026-04-25
Unknown · Projeto-Siga · CVE-2026-6990
**Name of the Vulnerable Software and Affected Versions** projeto-siga siga version 11.0.3.18 **Description** Cross site scripting can be initiated remotely via the manipulation of the `Nome/Descrição` argument within an unknown function of the '/sigawf/app/responsavel/novo' file. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-6716
8.8
2026-02-06
Unknown · Portabilis I-Educar · CVE-2026-2015
**Name of the Vulnerable Software and Affected Versions** Portabilis i-Educar versions up to 2.10 **Description** A weakness exists in Portabilis i-Educar up to version 2.10, specifically within the Final Status Import component. The issue involves improper authorization that can be triggered by manipulating the `school id` argument within an unknown function of the `FinalStatusImportService.php` file. This manipulation can be executed remotely. The exploit for this issue has been publicly released. The vendor was notified but did not respond. **Recommendations** Versions prior to 2.10 should be updated. As a temporary workaround, consider restricting access to the `FinalStatusImportService.php` file to minimize the risk of exploitation.