Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Assaf Alassaf

#44548of 56,335
6.4Total CVSS
Vulnerabilities · 2
Low
2
PT-2026-56134
3.3
2026-07-07
Coolify · Coolify · CVE-2026-34149
**Name of the Vulnerable Software and Affected Versions** Coolify versions prior to 4.0.0-beta.471 **Description** Coolify is an open-source tool for managing servers, applications, and databases. An authenticated user with database management permissions can execute commands on managed servers because the `DatabaseBackupJob` function interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell commands without adequate escaping. **Recommendations** Update to version 4.0.0-beta.471.
PT-2026-50609
3.1
2026-06-17
Drupal · Drupal · CVE-2026-55807
**Name of the Vulnerable Software and Affected Versions** Drupal core (affected versions not specified) **Description** The Media module supports oEmbed, which utilizes two discovery mechanisms: `providers.json` and URL discovery. The URL discovery code can be exploited to trick the system into making unauthorized server-side requests to any arbitrary URL. This is a Server-Side Request Forgery (SSRF), a flaw where an attacker can force a server to send requests to an unintended location. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.