Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nickc

#16895of 57,427
17.5Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-104607
7.5
2026-10-04
Ahsay · Ahsaycbs · CVE-2026-105133
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
PT-2026-104599
10
2026-10-03
Ahsay · Ahsaycbs · CVE-2026-105134
**Name of the Vulnerable Software and Affected Versions** Ahsay AhsayCBS versions prior to 10.3.4 **Description** An OS command injection flaw exists in the Replication Receiver component. A remote attacker can exploit this by manipulating the `random` argument within the '/rps/api/json/UpdateReceivers.do' endpoint, allowing for the execution of arbitrary operating system commands. **Recommendations** Upgrade to version 10.3.4.