Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hasan Anwar

#17626of 57,682
16.8Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-109987
7.0
2026-10-11
Imagemagick · Imagemagick · CVE-2026-108693
ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by bare name when Ghostscript is unregistered. Attackers can plant a malicious gswin64c.exe in the working directory to execute code with ImageMagick privileges when PDF, PostScript, or EPS files are converted.
PT-2026-109739
9.8
2026-10-10
Floci · Floci · CVE-2026-108598
**Name of the Vulnerable Software and Affected Versions** Floci versions 1.1.0 through 2.1.9 **Description** A code injection issue exists in the VtlTemplateEngine. Unauthenticated attackers can execute operating system commands within the Floci JVM by creating a REST API with a MOCK integration. This is achieved by using unrestricted Velocity mapping templates and `$util` reflection to access `Runtime` or `ProcessBuilder`. **Recommendations** Update Floci to version 2.2.0 or later.