Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Batuhan Er

#15307of 56,337
18.8Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-86823
9.8
2026-09-07
Next4Biz Information Technologies · Csm · CVE-2026-7861
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
PT-2025-32852
9.0
2025-08-12
Microsoft · Web Deploy · CVE-2025-53772
**Name of the Vulnerable Software and Affected Versions** Microsoft IIS Web Deploy versions prior to August 2025 PatchDay **Description** An issue exists in Microsoft Web Deploy where unsafe deserialization of HTTP header contents allows an authenticated attacker to execute code remotely. The vulnerability resides in the `msdeployagentservice` and `msdeploy.axd` endpoints. Specifically, the vulnerability involves insecure deserialization of GZip and Base64 encoded headers. Successful exploitation requires only low privileges and no user interaction. A proof-of-concept (PoC) exploit is publicly available. The vulnerability allows an authorized attacker to execute code over a network. **Recommendations** Apply security updates released on or after the August 2025 PatchDay. Restrict access to the `msdeploy.axd` and `msdeployagentservice` endpoints.