Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hotplugin0X01

#20367of 56,326
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-85508
7.5
2026-09-04
Openpanel Dev · Openpanel · CVE-2026-85612
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.
PT-2024-36402
6.5
2024-12-05
Unknown · Cyberpanel · CVE-2024-54679
**Name of the Vulnerable Software and Affected Versions** CyberPanel versions before 6778ad1 **Description** The issue concerns a lack of permission check for the `FilemanagerAdmin` capability when performing restart MySQL actions. This allows unauthorized access to restart MySQL without proper authorization. **Recommendations** For versions before 6778ad1, update to a version that includes the fix for this issue to ensure that the `FilemanagerAdmin` capability is properly checked for restart MySQL actions.