Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Abhishek Kushwaha

#16405of 57,427
17.9Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-103105
8.1
2026-09-30
Apache · Apache Mina Sshd · CVE-2026-93994
**Name of the Vulnerable Software and Affected Versions** Apache MINA SSHD versions prior to 2.20.0 Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5 **Description** The server code in the `sshd-core` component fails to enforce that multiple public keys presented during a multi-authentication scheme are distinct. This allows a user to bypass the requirement for two different key pairs by presenting the same single key twice, resulting in a partial authentication bypass. **Recommendations** Upgrade to version 2.20.0. Upgrade to version 3.0.0-M6.
PT-2026-98391
9.8
2026-09-25
Apache · Apache Qpid Broker-J · CVE-2026-92609
**Name of the Vulnerable Software and Affected Versions** Apache Qpid Broker-J versions prior to 10.1.1 **Description** Session fixation in the HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session. This occurs because the system reuses a session identifier that is retained across successful authentication, enabling session hijacking without requiring credentials. **Recommendations** Upgrade to version 10.1.1.