Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Pervinzahidli

#17727of 56,336
16.2Total CVSS
Vulnerabilities · 2
High
2
PT-2026-89292
7.5
2026-09-10
Undefined · Undefined · CVE-2026-77771
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second validation endpoint applies no attempt limit at all.
PT-2026-76952
8.7
2026-08-18
Arcadedb · Arcadedb · CVE-2026-75855
**Name of the Vulnerable Software and Affected Versions** ArcadeDB versions prior to 26.8.1 **Description** Authenticated root users can perform path traversal—a technique used to access files and directories outside the intended folder—by providing database names containing `../` sequences. This occurs because the software fails to sanitize database names within the create and drop database commands of the 'POST /api/v1/server' endpoint. Consequently, an attacker can create databases at arbitrary filesystem paths or recursively delete directories that the server process has permission to access. **Recommendations** Update ArcadeDB to version 26.8.1 or later.