Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hackus_Man

#22756of 56,326
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-68352
5.0
2026-08-05
Oblog · Oblog · CVE-2026-18968
**Name of the Vulnerable Software and Affected Versions** ttttonyhe OBlog versions up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f **Description** Remote attackers can perform cross site scripting (XSS) through the improper processing of the `/tags.php` endpoint. This occurs when the `day` argument is manipulated, allowing the execution of malicious scripts in the victim's browser. **Recommendations** Update ttttonyhe OBlog to a version later than 3ca6a45a2fcc81f6086751d8af124658720e8f8f. As a temporary workaround, restrict access to the `/tags.php` file or avoid using the `day` argument until a fix is applied.
PT-2026-23895
6.5
2026-03-08
Sourcecodester · Modern Image Gallery App · CVE-2026-3695
**Name of the Vulnerable Software and Affected Versions** SourceCodester Modern Image Gallery App version 1.0 **Description** A path traversal issue exists in SourceCodester Modern Image Gallery App version 1.0. The issue is located in the `/delete.php` file, specifically affecting an unknown function. Manipulation of the `filename` argument allows for path traversal, enabling remote attacks. The exploit details have been publicly disclosed. **Recommendations** As a temporary workaround, consider restricting access to the `/delete.php` file until a patch is available.