Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Windhxy

#16624de 56,337
17.3CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2026-69292
7.5
2026-08-09
Npm · Node-Sql-Query · CVE-2026-19351
**Nome do Software Vulnerável e Versões Afetadas** dresende node-sql-query versões 0.1.25 a 0.1.28 **Description** Um problema de injeção de SQL existe no componente Request Parameter Handler dentro da biblioteca `lib/Select.js`. A falha está localizada nas funções `SelectQuery.from()` e `SelectQuery.build()`, permitindo que um invasor remoto realize uma manipulação que resulte na execução de comandos SQL arbitrários. **Recommendations** Atualize para a versão 0.1.29.
PT-2025-38411
9.8
2025-09-18
Itsourcecode · Student Information Management System · CVE-2025-10673
**Name of the Vulnerable Software and Affected Versions** itsourcecode Student Information Management System version 1.0 **Description** A vulnerability exists in itsourcecode Student Information Management System version 1.0. The issue is a SQL injection affecting an unknown function within the `/admin/modules/class/index.php` file. The `classId` argument can be manipulated to trigger the injection. This manipulation can be initiated remotely. The exploit has been publicly disclosed. **Recommendations** As a temporary workaround, consider restricting access to the `/admin/modules/class/index.php` file until a fix is available.