Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

A1Batr0Ss

#21373of 56,330
13Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-72158
6.4
2026-08-15
WordPress · Beaver Builder Page Builder · CVE-2026-17090
**Name of the Vulnerable Software and Affected Versions** Beaver Builder Page Builder versions prior to 2.10.2.3 **Description** The Beaver Builder Page Builder plugin for WordPress contains a stored cross-site scripting issue. This occurs due to insufficient input sanitization and output escaping within the Button Module `button` (Button Code) setting. Authenticated attackers with author-level access or higher can inject arbitrary web scripts into pages. These scripts execute automatically when any user visits the affected page. By default, the plugin grants editor access to any WordPress role with the `edit posts` capability, allowing users with the Author role and above to perform this action. **Recommendations** Update the plugin to a version newer than 2.10.2.2. Restrict access to the `button` setting in the Button Module for users with Author-level permissions until the update is applied.
PT-2025-32263
6.6
2025-08-07
Ollama · Ollama · CVE-2025-44779
**Name of the Vulnerable Software and Affected Versions** Ollama version 0.1.33 **Description** An issue allows attackers to delete arbitrary files by sending a crafted packet to the `/api/pull` endpoint. **Recommendations** Update to a newer version that contains a fix for this issue. As a temporary workaround, restrict access to the `/api/pull` endpoint.