Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Xndrdev

#22620of 56,327
11.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-53890
4.8
2026-06-30
Coolify · Coolify · CVE-2026-27882
**Name of the Vulnerable Software and Affected Versions** Coolify versions prior to 4.0.0-beta.461 **Description** The GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation allows for timing attacks, where an attacker can gradually discover the secret token by measuring differences in response times. A timing attack is a side-channel attack where the attacker attempts to compromise a system by analyzing the time it takes to execute specific algorithms. **Recommendations** Update to version 4.0.0-beta.461.
PT-2026-7163
6.9
2026-02-09
Shopware · Froshadminer · CVE-2026-25878
**Name of the Vulnerable Software and Affected Versions** FroshAdminer versions prior to 2.2.1 **Description** The Adminer route ('/admin/adminer') within the FroshAdminer plugin for Shopware Platform was accessible without requiring Shopware admin authentication. The route was configured without authentication and session validation, potentially exposing the Adminer user interface to unauthorized users. **Recommendations** Update FroshAdminer to version 2.2.1 or later.