Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

B1D0Ws

#22668of 56,330
11.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-85272
6.5
2026-09-03
Specterops · Bloodhound · CVE-2026-85241
A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.
PT-2025-22316
5.1
2025-05-20
Part-Db · Part-Db · CVE-2025-5007
**Name of the Vulnerable Software and Affected Versions** Part-DB versions up to 1.17.0 **Description** A vulnerability was found in the Profile Picture Feature of Part-DB, affecting the `handleUpload` function of the `AttachmentSubmitHandler.php` file. The manipulation of the `attachment` argument leads to cross-site scripting. The attack can be launched remotely. **Recommendations** For Part-DB versions up to 1.17.0, upgrade to version 1.17.1 to address this issue. As a temporary workaround, consider restricting the use of the `handleUpload` function of the `AttachmentSubmitHandler.php` file until the upgrade is applied.